Information processing methods, network device, terminal, communication system and storage medium

By negotiating the authentication encryption algorithm in the communication system, the problem of not supporting the AE algorithm in the communication system is solved, the negotiation of confidentiality and integrity protection is realized, and the security and negotiation efficiency of the communication system are improved.

WO2025213303A1PCT designated stage Publication Date: 2025-10-16BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/086447
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-07
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

The communication system does not support negotiation of the Authentication and Encryption (AE) algorithm.

Method used

A message including an algorithm identifier is sent to the terminal through a network device, and the terminal and a second network element send policy information to negotiate an authenticated encryption (AE) algorithm to support negotiation of the AE algorithm.

Benefits of technology

The negotiation of AE algorithm in the communication system is realized, the negotiation of confidentiality and integrity protection is supported, and the security and negotiation efficiency are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024086447_16102025_PF_FP_ABST
    Figure CN2024086447_16102025_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure provide information processing methods, a network device, a terminal, a communication system and a storage medium. An information processing method is executed by a network device, and comprises: sending a first message to a terminal, wherein the first message comprises an algorithm identifier, and the algorithm identifier is used for the terminal to determine an AE algorithm for performing security-related processing, such that a communication system (i.e., between the network device and the terminal) supports negotiation of the AE algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, network device, terminal, communication system, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to an information processing method, a network device, a terminal, a communication system, and a storage medium. BACKGROUND

[0002] In the technical field of communication, messages of a Non Access Stratum (NAS) and / or an Access Stratum (AS) need to be protected in security; the security protection can include confidentiality protection and / or integrity protection.

[0003] SUMMARY

[0004] Embodiments of the present disclosure need to solve the problem of negotiation of an AE algorithm not being supported in a communication system.

[0005] According to a first aspect of embodiments of the present disclosure, an information processing method is provided, executed by a network device, comprising: sending a first message to a terminal, wherein the first message comprises an algorithm identifier; and the algorithm identifier is used by the terminal to determine an Authenticated Encryption (AE) algorithm for security-related processing.

[0006] According to a second aspect of embodiments of the present disclosure, an information processing method is provided, executed by a terminal, comprising: receiving a first message sent by a network device, wherein the first message comprises an algorithm identifier; and the algorithm identifier is used by the terminal to determine an Authenticated Encryption (AE) algorithm for security-related processing.

[0007] According to a third aspect of embodiments of the present disclosure, an information processing method is provided, executed by a second network element, comprising: receiving policy information sent by a third network element; and sending the policy information to an access network device; wherein the policy information comprises one of the following: a first policy indication indicating that an Authenticated Encryption (AE) or partial encryption must be used; a second policy indication indicating that an Authenticated Encryption (AE) or partial encryption is preferred to be used; and a third policy indication indicating that an Authenticated Encryption (AE) or partial encryption does not need to be used.

[0008] According to a fourth aspect of embodiments of the present disclosure, a network device is provided, comprising: a first transceiver configured to send a first message to a terminal, wherein the first message comprises an algorithm identifier; and the algorithm identifier is used by the terminal to determine an Authenticated Encryption (AE) algorithm for security-related processing.

[0009] According to a fifth aspect of the embodiments of the present disclosure, a terminal is provided, including: a second transceiver configured to receive a first message sent by a network device, wherein the first message includes an algorithm identifier; and the algorithm identifier is used by the terminal to determine an authentication encryption (AE) algorithm for related processing.

[0010] According to a sixth aspect of the embodiments of the present disclosure, a second network element is provided, including: a third transceiver configured to receive policy information sent by a third network element; and the third transceiver is further configured to send the policy information to an access network device; wherein the policy information includes one of: a first policy indication indicating that authentication encryption or partial encryption must be used; a second policy indication indicating that authentication encryption or partial encryption is preferred to be used; and a third policy indication indicating that authentication encryption or partial encryption does not need to be used.

[0011] According to a seventh aspect of the embodiments of the present disclosure, a communication device is provided, including one or more processors; and the communication device is configured to perform the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0012] According to an eighth aspect of the embodiments of the present disclosure, a communication system is provided, including: a network device, a terminal and a second network element; wherein the network device is configured to perform the method described in the optional implementation of the first aspect, the terminal is configured to perform the method described in the optional implementation of the second aspect, and the second network element is configured to perform the method described in the optional implementation of the third aspect.

[0013] According to a ninth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, when the instructions are executed on a communication device, the communication device performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0014] According to a tenth aspect of the embodiments of the present disclosure, a computer program product is provided, and the computer program product includes a computer program or instructions, and the computer program or instructions are executed by a processor to implement the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0015] The embodiments of the present disclosure can enable the communication system to support negotiation of AE algorithms. BRIEF DESCRIPTION OF DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0017] FIG. 1 is a structural schematic diagram of an information processing system according to an embodiment of the present disclosure.

[0018] FIG. 2 is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0019] FIG. 3A is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0020] FIG. 3B is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0021] FIG. 4A is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0022] FIG. 4B is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0023] FIG. 5A is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0024] FIG. 5B is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0025] FIG. 6 is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0026] FIG. 7A is a schematic diagram of the relationship between AEAD negotiation mechanisms according to an embodiment of the present disclosure.

[0027] FIG. 7B is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0028] FIG. 7C is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0029] FIG. 8A is a structural schematic diagram of a network device according to an embodiment of the present disclosure.

[0030] FIG. 8B is a structural schematic diagram of a terminal according to an embodiment of the present disclosure.

[0031] FIG. 8C is a structural schematic diagram of a second network element according to an embodiment of the present disclosure.

[0032] FIG. 9A is a structural schematic diagram of a communication device according to an embodiment of the present disclosure.

[0033] FIG. 9B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0034] The embodiments of the present disclosure provide an information processing method, a network device, a terminal, a communication system and a storage medium.

[0035] In the first aspect, the embodiments of the present disclosure provide an information processing method, performed by a network device, comprising: sending a first message to a terminal, wherein the first message comprises an algorithm identifier; and the algorithm identifier is used by the terminal to determine an Authenticated Encryption (AE) algorithm for security-related processing.

[0036] In the above embodiments, the negotiation of the AE algorithm is supported in the communication system (i.e., between the network device and the terminal).

[0037] In combination with some embodiments of the first aspect, in some embodiments, the AE algorithm is an Authenticated Encryption with Associated Data (AEAD) algorithm.

[0038] In the above embodiments, the negotiation of the AEAD algorithm is supported in the communication system.

[0039] In combination with some embodiments of the first aspect, in some embodiments, the first message is further used to determine a working mode of the AE algorithm; and the working mode is one of: confidentiality protection and integrity protection; integrity protection; and confidentiality protection.

[0040] In the above embodiments, the negotiation of the working mode of the AE algorithm is supported in the communication system; for example, the negotiation of the working mode of the AE algorithm in which the confidentiality protection and the integrity protection are supported, or the integrity protection is supported.

[0041] In combination with some embodiments of the first aspect, in some embodiments, the confidentiality protection and the integrity protection comprise one of: unified confidentiality protection and integrity protection; and separate confidentiality protection and integrity protection.

[0042] In the above embodiments, it is defined that the confidentiality protection and the integrity protection can be executed in a unified manner, or can be executed in a separate manner. Here, when the confidentiality protection and the integrity protection are executed in a unified manner, only one property is used to complete the confidentiality protection and the integrity protection.

[0043] In combination with some embodiments of the first aspect, in some embodiments, the first message comprises a working mode indication; and the working mode indication is used to indicate that the working mode is: the confidentiality protection and the integrity protection, or the integrity protection, or the confidentiality protection.

[0044] In the above embodiments, the working mode of the AE algorithm can be accurately determined through the working mode indication carried in the first message.

[0045] In some embodiments of the first aspect, in some embodiments, when the first message does not comprise the indication of the operation mode, the first message is configured to indicate that the operation mode is confidentiality protection and integrity protection; or, when the first message does not comprise the indication of the operation mode but comprises the algorithm identification, the algorithm identification is further configured to indicate the operation mode.

[0046] In the above embodiments, when the first message does not carry the indication of the operation mode, it can be directly determined that the operation mode of the AE algorithm is confidentiality protection and integrity protection. Alternatively, when the first message does not comprise the indication of the operation mode, the operation mode of the AE algorithm can also be determined through the algorithm identification. In this way, the operation mode of the AE algorithm can be identified even when the first message does not comprise the indication of the operation mode. Moreover, when the algorithm identification is further configured to determine the operation mode, the function of the algorithm identification is enhanced.

[0047] In some embodiments of the first aspect, in some embodiments, the algorithm identification comprises at least one of: a first algorithm identification, a second algorithm identification, and / or a third algorithm identification; the first algorithm identification, the second algorithm identification, and the third algorithm identification each comprises at least one of: a first algorithm indication, configured to indicate that the operation mode is integrity protection; a second algorithm indication, configured to indicate that the operation mode is confidentiality protection; a third algorithm indication, configured to indicate that the operation mode is confidentiality protection and integrity protection; a fourth algorithm indication, configured to indicate that the operation mode is no integrity protection; and a fifth algorithm indication, configured to indicate that the operation mode is no confidentiality protection.

[0048] In the above embodiments, the operation mode of the specific AE algorithm can be accurately determined through different algorithm indications in the algorithm identification.

[0049] In some embodiments of the first aspect, in some embodiments, the algorithm identification comprises at least one of: a first algorithm identification, configured to indicate a Snow 5G-based AE algorithm; a second algorithm identification, configured to indicate an AES-256-based AE algorithm; and a third algorithm identification, configured to indicate a ZUC-256-based AE algorithm.

[0050] In the above embodiments, different algorithms can be accurately indicated through different algorithm identifications.

[0051] In some embodiments of the first aspect, in some embodiments, the first message further comprises at least one of: a random number; a cipher text; an indication of the operation mode; a Non-access stratum (NAS) message authentication code (MAC); an access stratum message authentication code (MAC-I); a first length, the first length being used to indicate a length of the NAS MAC; a second length, the second length being used to indicate a length of the MAC-I; a key indicator, the key indicator being used to indicate an intermediate key; and a terminal capability indication, the terminal capability indication being used to indicate an algorithm identity of an AE algorithm supported by the terminal.

[0052] In the above embodiments, the AE algorithm can be negotiated through the first message, and the terminal can be caused to perform confidentiality protection and / or integrity protection based on the random number, the first length, the NAS-MAC, the second length, the MAC-I, the algorithm identity, and the like included in the first message.

[0053] In some embodiments of the first aspect, in some embodiments, the network device is a first network element; and the first message comprises at least one of: a random number; a cipher text; an algorithm identity; an indication of the operation mode; a NAS MAC; a first length; a key indicator; and terminal capability information.

[0054] In the above embodiments, the first messages sent by the first network element can cause the communication system to perform AE algorithm negotiation for NAS messages and to perform confidentiality and / or integrity protection for the NAS messages.

[0055] In some embodiments of the first aspect, in some embodiments, the first network element is an Access and Mobility Management Function (AMF).

[0056] In some embodiments of the first aspect, in some embodiments, the network device is an access network device; and the first message comprises at least one of: a random number; a cipher text; an algorithm identity; an indication of the operation mode; a MAC-I; a second length; a key indicator; and terminal capability information.

[0057] In the above embodiments, the first messages sent by the access network device can cause the communication system to perform AE algorithm negotiation for RRC messages or UP messages and to perform confidentiality and / or integrity protection for the RRC messages or the UP messages.

[0058] In some embodiments of the first aspect, in some embodiments, the algorithm identifier is used to indicate an AE algorithm related to a Radio Resource Control (RRC) message or a User Plane (UP) message; or the working mode indicator is used to indicate a working mode related to the RRC message or the UP message.

[0059] In the above examples, the AE algorithm related to the RRC message or the UP message can be distinguished, and / or the working mode of the AE algorithm related to the RRC message or the UP message can be distinguished.

[0060] In some embodiments of the first aspect, in some embodiments, the method further comprises: obtaining policy information from the second network element; wherein the policy information comprises one of the following: a first policy indication indicating that authentication encryption or partial encryption must be used; a second policy indication indicating that authentication encryption or partial encryption is preferred to be used; and a third policy indication indicating that authentication encryption or partial encryption does not need to be used.

[0061] In the above embodiments, the network device can obtain the policy information, so as to determine whether the network device must or prefers to use authentication encryption or partial encryption, etc.

[0062] In some embodiments of the first aspect, in some embodiments, when the working mode is unified confidentiality protection and integrity protection, the associated data of the AE algorithm comprises at least one of the following: a key indicator, an algorithm identifier, a NAS MAC, a first length, a random number, and a working mode indicator; or when the working mode is unified confidentiality protection and integrity protection, the associated data of the AE algorithm comprises at least one of the following: a key indicator, an algorithm identifier, a MAC-I, a second length, a random number, and a working mode indicator.

[0063] In the above embodiments, the associated data can not be encrypted but only integrity protected.

[0064] In some embodiments of the first aspect, in some embodiments, when the working mode is separate confidentiality protection and integrity protection, the first message does not comprise a ciphertext; or when the working mode is integrity protection, the first message does not comprise a ciphertext.

[0065] In the above embodiments, it can be determined that when the working mode is integrity protection or confidentiality and integrity protection, the first message can not comprise a ciphertext, and at this time, the security-related processing between the communication systems is not affected.

[0066] In some embodiments of the first aspect, in some embodiments, the first message comprises a random number, and the random number is used by the terminal to determine the expected NAS MAC or the expected MAC-I.

[0067] In the above embodiments, the NAS MAC or the MAC-I used for integrity verification can be accurately determined based on the random number, thereby facilitating improvement of the accuracy of integrity verification.

[0068] In the second aspect, the embodiments of the present disclosure provide an information processing method, performed by a terminal, comprising: receiving a first message sent by a network device, wherein the first message comprises an algorithm identifier; and the algorithm identifier is used by the terminal to determine an AE algorithm for security-related processing.

[0069] In some embodiments of the second aspect, in some embodiments, the AE algorithm is AEAD.

[0070] In some embodiments of the second aspect, in some embodiments, the first message is further used to determine a working mode of the AE algorithm; and the working mode is one of: confidentiality protection and integrity protection; integrity protection; and confidentiality protection.

[0071] In some embodiments of the second aspect, in some embodiments, the confidentiality protection and the integrity protection comprise one of: unified confidentiality protection and integrity protection; and separate confidentiality protection and integrity protection.

[0072] In some embodiments of the second aspect, in some embodiments, the first message comprises a working mode indication; and the working mode indication is used to indicate that the working mode is: confidentiality protection and integrity protection, or integrity protection, or confidentiality protection.

[0073] In some embodiments of the second aspect, in some embodiments, the method further comprises: determining, based on the first message not comprising the working mode indication, that the working mode is confidentiality protection and integrity protection; or determining, based on the first message not comprising the working mode indication but comprising the algorithm identifier, the working mode according to the algorithm identifier.

[0074] In some embodiments of the second aspect, in some embodiments, the algorithm identifier comprises at least one of: a first algorithm identifier, a second algorithm identifier, and / or a third algorithm identifier; and each of the first algorithm identifier, the second algorithm identifier, and the third algorithm identifier comprises at least one of: a first algorithm indication used to indicate that the working mode is integrity protection; a second algorithm indication used to indicate that the working mode is confidentiality protection; a third algorithm indication used to indicate that the working mode is confidentiality protection and integrity protection; a fourth algorithm indication used to indicate that the working mode is no integrity protection; and a fifth algorithm indication used to indicate that the working mode is no confidentiality protection.

[0075] In some embodiments of the second aspect, in some embodiments, the algorithm identification comprises at least one of: a first algorithm identification indicating a Snow 5G based AE algorithm; a second algorithm identification indicating an AES-256 based AE algorithm; and a third algorithm identification indicating a ZUC-256 based AE algorithm.

[0076] In some embodiments of the second aspect, in some embodiments, the first message comprises at least one of: a random number; a cipher text; a working mode indication indicating a working mode; a NAS MAC; a MAC-I; a first length indicating a length of the NAS MAC; a second length indicating a length of the MAC-I; a key indicator indicating an intermediate key; and a terminal capability indication indicating algorithm identifications of AE algorithms supported by the terminal.

[0077] In some embodiments of the second aspect, in some embodiments, the network device is a first network element; and the first message comprises at least one of: a random number; a cipher text; an algorithm identification; a working mode indication; a NAS MAC; a first length; a key indicator; and terminal capability information.

[0078] In some embodiments of the second aspect, in some embodiments, the network device is an access network device; and the first message comprises at least one of: a random number; a cipher text; an algorithm identification; a working mode indication; a MAC-I; a second length; a key indicator; and terminal capability information.

[0079] In some embodiments of the second aspect, in some embodiments, the algorithm identification indicates an AE algorithm related to RRC messages or indicates an AE algorithm related to UP messages; or the working mode indication indicates a working mode related to RRC messages or indicates a working mode related to UP messages.

[0080] In some embodiments of the second aspect, in some embodiments, the working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm comprises at least one of: the key indicator, the algorithm identification, the NAS MAC, the first length, the random number, and the working mode indication; or the working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm comprises at least one of: the key indicator, the algorithm identification, the MAC-I, the second length, the random number, and the working mode indication.

[0081] In some embodiments of the second aspect, in some embodiments, the working mode is separate confidentiality protection and integrity protection, and no cipher text is included in the first message; or the working mode is integrity protection, and no cipher text is included in the first message.

[0082] In some embodiments of the second aspect, in some embodiments, the first message includes a random number, and the random number is used by the terminal to determine the expected NAS MAC or the expected MAC-I.

[0083] In some embodiments of the second aspect, in some embodiments, the method further includes at least one of the following: based on the terminal capability indication stored by the terminal being different from the terminal capability indication in the first message, sending a rejection message to the first network element or sending a rejection message to the access network device; based on the terminal determining that the length of the received NAS MAC is different from the first length, sending a rejection message to the first network element; and based on the terminal determining that the length of the received MAC-I is different from the second length, sending a rejection message to the access network device.

[0084] In a third aspect, the embodiments of the present disclosure provide an information processing method, executed by a second network element, including: receiving policy information sent by a third network element; and sending the policy information to an access network device; wherein the policy information includes one of the following: a first policy indication indicating that authentication encryption or partial encryption must be used; a second policy indication indicating that authentication encryption or partial encryption is preferred to be used; and a third policy indication indicating that authentication encryption or partial encryption does not need to be used.

[0085] In some embodiments of the third aspect, in some embodiments, the second network element is a session management function (SMF); and / or the third network element is a unified data management function (UDM).

[0086] In a fourth aspect, the embodiments of the present disclosure provide a network device, including: a first transceiver module configured to send a first message to a terminal, wherein the first message includes an algorithm identifier; and the algorithm identifier is used by the terminal to determine an authentication encryption (AE) algorithm for security-related processing.

[0087] In a fifth aspect, the embodiments of the present disclosure provide a terminal, including: a second transceiver module configured to receive a first message sent by a network device, wherein the first message includes an algorithm identifier; and the algorithm identifier is used by the terminal to determine an authentication encryption (AE) algorithm for related processing.

[0088] In a sixth aspect, the embodiments of the present disclosure provide a second network element, comprising: a third transceiver configured to receive policy information sent by a third network element; and the third transceiver configured to send the policy information to an access network device; wherein the policy information comprises one of: a first policy indication indicating that authentication encryption or partial encryption must be used; a second policy indication indicating that authentication encryption or partial encryption is preferred to be used; and a third policy indication indicating that authentication encryption or partial encryption does not need to be used.

[0089] In a seventh aspect, the embodiments of the present disclosure provide a communication device, comprising one or more processors; wherein the communication device is configured to perform the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0090] In an eighth aspect, the embodiments of the present disclosure provide a communication system, comprising: a network device, a terminal and a second network element; wherein the network device is configured to perform the method described in the optional implementation of the first aspect, the terminal is configured to perform the method described in the optional implementation of the second aspect, and the second network element is configured to perform the method described in the optional implementation of the third aspect.

[0091] In a ninth aspect, the embodiments of the present disclosure provide a storage medium, wherein the storage medium stores instructions, and when the instructions run on a communication device, the communication device performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0092] In a tenth aspect, the embodiments of the present disclosure provide a computer program product, comprising a computer program or instructions, and when the computer program or instructions are executed by a processor, the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect is implemented.

[0093] In an eleventh aspect, the embodiments of the present disclosure provide a computer program, when the computer program runs on a computer, the computer performs the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0094] In a twelfth aspect, the embodiments of the present disclosure provide a chip or chip system, comprising processing circuitry configured to perform the method described in the first aspect, the second aspect, the third aspect, or the optional implementation of the first aspect, the second aspect and the third aspect.

[0095] It can be understood that the network device, the terminal, the communication device, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are used to execute the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here.

[0096] The embodiments of the present disclosure provide an information processing method, a network device, a terminal, a communication system and a storage medium. In some embodiments, the information processing method and the communication method can be replaced with each other, the information processing device and the communication device can be replaced with each other, and the information processing system and the communication system can be replaced with each other.

[0097] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or part of the steps of different embodiments can be combined arbitrarily, and an embodiment can be combined with the optional implementation manners of other embodiments.

[0098] In the embodiments of the present disclosure, the terms and / or descriptions between the embodiments are consistent and can be used with each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0099] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.

[0100] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as “one”, “a”, “the”, “above”, “said”, “preceding”, “this” and the like, can represent “one and only one”, or “one or more”, “at least one” and the like. For example, in the case of using articles such as “a”, “an”, “the” and the like in English, the noun after the article can be understood as singular expression, or can be understood as plural expression.

[0101] In the embodiments of the present disclosure, “a plurality of” means two or more.

[0102] In some embodiments, the terms "at least one of," "one or more of," "a plurality of," "multiple," and the like can be used interchangeably.

[0103] In some embodiments, the recitations "at least one of A, B," "A and / or B," "in one case A, in another case B," "in response to a case A, in response to a case B," and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B (A and B are executed). When there are more branches such as A, B, C, and the like, the above is similar.

[0104] In some embodiments, the recitations "A or B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above is similar.

[0105] The prefix words "first", "second", and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor do they limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the description objects are "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.

[0106] In some embodiments, "comprising", "including", "to indicate", "carrying", can be interpreted as directly carrying A, and can also be interpreted as indirectly indicating A.

[0107] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0108] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0109] In some embodiments, the device and the like can be interpreted as physical or virtual, and the name is not limited to the name described in the embodiments. The terms "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0110] In some embodiments, "network" can be interpreted as a device (for example, access network device, core network device, etc.) contained in the network.

[0111] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.

[0112] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0113] In some embodiments, an access network device, a core network device, or a network device can be replaced with a terminal. For example, for a structure in which communication between an access network device, a core network device, or a network device and a terminal is replaced with communication between a plurality of terminals (for example, also referred to as device-to-device (D2D), vehicle-to-everything (V2X), and so on), embodiments of the present disclosure can also be applied. In this case, a structure in which a terminal has all or part of the functions of an access network device can also be provided. Furthermore, the language of "uplink," "downlink," and so on can also be replaced with language corresponding to communication between terminals (for example, "side"). For example, an uplink channel, a downlink channel, and so on can be replaced with a side channel, and an uplink, a downlink, and so on can be replaced with a side link.

[0114] In some embodiments, a terminal can be replaced with an access network device, a core network device, or a network device. In this case, a structure in which an access network device, a core network device, or a network device has all or part of the functions of a terminal can also be provided.

[0115] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country in which the location is situated.

[0116] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0117] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0118] FIG. 1 is a structural schematic diagram of an information processing system 100 according to an embodiment of the present disclosure. As shown in FIG. 1, the information processing system 100 can include a terminal 101 and a network device 102.

[0119] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.

[0120] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an IOT device or terminal, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a VR terminal device, an AR terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, etc., but is not limited thereto.

[0121] In some embodiments, the access network device is at least one of a node or a device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0122] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.

[0123] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and the functions of part of the protocol layers are controlled by the CU, and the functions of the remaining part or all of the protocol layers are distributed in the DU and controlled by the CU, but are not limited thereto.

[0124] In some embodiments, the core network device can be one device, including the first device, the second device, etc., or a plurality of devices or device groups, respectively including all or part of the above-mentioned first device and second device. The first device and the second device can be network elements; the network elements can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next generation core (NGC), etc.

[0125] It can be understood that the information processing system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0126] The following embodiments of the present disclosure can be applied to the information processing system 100 shown in FIG. 1, or part of the subject, but are not limited thereto. The subjects shown in FIG. 1 are exemplary, and the information processing system can include all or part of the subjects in FIG. 1, or other subjects other than those in FIG. 1. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0127] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).

[0128] In some embodiments, in a legacy communication system (e.g., a system such as 5G), two types of security mechanisms (confidentiality mechanism and integrity mechanism) can be used to protect NAS messages and / or AS messages; in order to provide confidentiality and integrity protection of the messages by these mechanisms, the messages can be respectively subjected to confidentiality protection and integrity protection.

[0129] In some embodiments, Authenticated Encryption (AE) is an encryption scheme that simultaneously ensures data confidentiality and authenticity. Among them, Authenticated Encryption with Associated Data (AEAD) is a variant of AE, which allows "associated data (AD)" to be included in the message. The associated data is additional non-confidential information; the associated data is also called Attachment authentication data (ADD).

[0130] In some embodiments, AE algorithms can be introduced in the communication system so that the efficiency of security procedures can be improved, etc. Before the communication system adopts AE algorithms, it is found that the traditional security algorithm negotiation mechanism in the communication system only supports the selection of confidentiality mechanisms and integrity mechanisms (i.e., does not support the indication of AEAD algorithms). In addition, the traditional negotiation mechanism cannot support the indication of MAC size; however, the newly introduced AEAD algorithm may support two MAC sizes (for example, 32 bits and 64 bits).

[0131] Embodiments of the present disclosure enable the communication system to support the negotiation of AE algorithms (such as AEAD algorithms).

[0132] Figure 2 is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2, the information processing method of the present embodiment is used in the information processing system 100, and the method comprises:

[0133] In step S2101, the second network element sends policy information to the access network device.

[0134] In some embodiments, the access network device receives the policy information sent by the second network element.

[0135] Optionally, the second network element is an SMF, and the access network device is a base station.

[0136] In some optional embodiments, before step S2101, the second network element further receives policy information sent by a third network element. Optionally, the third network element sends the policy information to the second network element. Optionally, the third network element is a UDM.

[0137] In some embodiments, the policy information is used to determine whether to use authenticated encryption or partial encryption. Optionally, the partial encryption can include AEAD.

[0138] In some embodiments, the policy information includes a first policy indication, a second policy indication, or a third policy indication.

[0139] Optionally, the first policy indicates that authentication encryption or partial encryption must be used. Illustratively, the first policy indicates that authentication encryption or partial encryption must be used for all traffic on a PDU session.

[0140] Optionally, the second policy indicates that authentication encryption or partial encryption is preferred. Illustratively, the first policy indicates that authentication encryption or partial encryption is preferred for all traffic on a PDU session.

[0141] Optionally, the third policy indicates that authentication encryption or partial encryption is not required. Illustratively, the first policy indicates that authentication encryption or partial encryption is not used for a PDU session.

[0142] In some embodiments, the policy information can include a fourth policy indication, a fifth policy indication, a sixth policy indication, a seventh policy indication, an eighth policy indication, and a ninth policy information.

[0143] Optionally, the fourth policy indicates that integrity protection must be used. Illustratively, the fourth policy indicates that integrity protection must be used for all traffic on a PDU session.

[0144] Optionally, the fifth policy indicates that integrity protection is preferred. Illustratively, the fifth policy indicates that integrity protection is preferred for all traffic on a PDU session.

[0145] Optionally, the sixth policy indicates that integrity protection is not required. Illustratively, the sixth policy indicates that integrity protection is not used for a PDU session.

[0146] Optionally, the seventh policy indicates that confidentiality protection must be used. Illustratively, the seventh policy indicates that confidentiality protection must be used for all traffic on a PDU session.

[0147] Optionally, the eighth policy indicates that confidentiality protection is preferred. Illustratively, the eighth policy indicates that confidentiality protection is preferred for all traffic on a PDU session.

[0148] Optionally, the ninth policy indicates that confidentiality protection is not required. Illustratively, the ninth policy indicates that confidentiality protection is not used for a PDU session.

[0149] Optionally, the first policy indication, the second policy indication, the third policy indication, the fourth policy indication, the fifth policy indication, the sixth policy indication, the seventh policy indication, the eighth policy indication, and the ninth policy information are each one or more bits.

[0150] Optionally, the first policy indication, the second policy indication, the third policy indication, the fourth policy indication, the fifth policy indication, the sixth policy indication, the seventh policy indication, the eighth policy indication, and the ninth policy information are each one or more bits.

[0151] In some embodiments, the name of the policy information is not limited, which is, for example, UP policy information or UP security policy or UP policy or UP policy indication, etc.

[0152] In some optional embodiments, after step S2101, the access network device determines whether to use authentication encryption or partial encryption based on the policy information.

[0153] In step S2102, the network device sends a first message to the terminal.

[0154] In some embodiments, the terminal receives the first message sent by the network device.

[0155] Optionally, the network device includes an access network device and / or a core network device. For example, the access network device can include a base station; and the core network device is a first network element. For example, the first network element can be an AMF.

[0156] In some embodiments, the first message includes an algorithm identifier. Optionally, the algorithm identifier is used by the terminal to determine an AE algorithm for security-related processing. Optionally, the algorithm identifier is used to indicate an AE algorithm for security-related processing. Optionally, the algorithm identifier is an identifier of an AE algorithm for security-related processing.

[0157] In some embodiments, the AE algorithm is an AEAD algorithm. In the embodiments of the present disclosure, the AE can include an AEAD; and the AE algorithm can include an AEAD algorithm.

[0158] Optionally, the security-related processing can include confidentiality-related processing and / or integrity protection-related processing. The confidentiality-related processing can include encryption operation or decryption operation. The integrity protection-related processing can include integrity protection or integrity check (or verification).

[0159] Optionally, the security-related processing can include confidentiality protection and / or integrity protection. For example, the security-related processing can include confidentiality protection, integrity protection, confidentiality protection and integrity protection; and the confidentiality protection and integrity protection can include unified confidentiality protection and integrity protection, or separate confidentiality protection and integrity protection.

[0160] Optionally, the security related processing can include: confidentiality computation and integrity computation. The confidentiality computation can refer to confidentiality protection or confidentiality related processing; the integrity computation can refer to integrity protection or integrity related processing.

[0161] Optionally, the unified confidentiality protection and integrity protection means that the confidentiality protection and the integrity protection are completed by one key.

[0162] Optionally, the separate confidentiality protection and integrity protection means that the confidentiality protection is completed by one key first, and then the integrity protection is completed by another key; or the integrity protection is completed by one key first, and then the confidentiality protection is completed by one key.

[0163] Optionally, the key for the confidentiality protection can be a confidentiality key (e.g., Cipher Key, CK); the key for the integrity protection can be an integrity key (e.g., Integrity Key, IK); the key for the unified confidentiality protection and integrity protection can be the same key (Unified Key, UK); the keys for the separate confidentiality protection and integrity protection can be the confidentiality key and the integrity key.

[0164] In some embodiments, the algorithm identification includes at least one of: a first algorithm identification, a second algorithm identification, and a third algorithm identification.

[0165] Optionally, the first algorithm identification is used to indicate a Snow 5G based AE algorithm. For example, the first algorithm identification is used to indicate a Snow 5G based AEAD algorithm.

[0166] Optionally, the second algorithm identification is used to indicate an AES-256 based AE algorithm. For example, the second algorithm identification is used to indicate an AES-256 based AEAD algorithm.

[0167] Optionally, the third algorithm identification is used to indicate a ZUC-256 based AE algorithm. For example, the third algorithm identification is used to indicate a ZUC-256 based AEAD algorithm.

[0168] Optionally, the name of the algorithm identification is not limited, which is, for example, AE identification or AEAD identification or AE algorithm identification or AEAD algorithm identification or first identification, etc.

[0169] In some embodiments, the first message is further used to determine the working mode of the AE algorithm, or the first message is further used to indicate the working mode of the AE algorithm.

[0170] Optionally, the working mode is: confidentiality protection, or, confidentiality protection and integrity protection, or, integrity protection.

[0171] Optionally, the confidentiality protection and the integrity protection include: unified confidentiality protection and integrity protection; or, separate confidentiality protection and integrity protection.

[0172] Optionally, the first message is further used to determine: the working mode of the unified confidentiality protection and integrity protection of the AE algorithm, the working mode of the separate confidentiality protection and integrity protection of the AE algorithm, or the working mode of the integrity protection.

[0173] Optionally, the first message is further used to determine: the working mode of the unified confidentiality algorithm and integrity algorithm of the AE algorithm, the working mode of the separate confidentiality algorithm and integrity algorithm of the AE algorithm, or the working mode of the integrity algorithm.

[0174] In some embodiments, the first message can include at least one of: an algorithm identity, a random number, cipher text, a working mode indication, a NAS MAC, a MAC-I, a first length, a second length, a key indicator, and a terminal capability indication.

[0175] Optionally, the working mode indication is used to indicate the working mode. Optionally, the working mode indication is used to indicate the working mode of at least one of: unified confidentiality protection and integrity protection, separate confidentiality protection and integrity protection, or integrity protection.

[0176] Optionally, the name of the working mode indication is not limited, which is, for example, a first indication or working mode information or working mode, etc.

[0177] Optionally, the NAS MAC is a MAC for a NAS message.

[0178] Optionally, the name of the NAS MAC is not limited, which is, for example, a first MAC, etc.

[0179] Optionally, the MAC-I is a MAC for an RRC message.

[0180] Optionally, the name of the MAC-I is not limited, which is, for example, a second MAC or AS MAC, etc.

[0181] Optionally, the first length can be the length of the NAS MAC. For example, the first length can be 32 bits or 64 bits, etc.

[0182] Optionally, the second length can be the length of the MAC-I or AS MAC. For example, the second length can be 32 bits or 64 bits, etc.

[0183] Optionally, the key indicator is used to indicate an intermediate key. The intermediate key is used to generate a confidentiality key, an integrity key, and / or a unified key, etc.

[0184] Optionally, the terminal capability indication is used to indicate an algorithm identification of an AE algorithm supported by the terminal.

[0185] In some embodiments, the algorithm identification, the random number, the cipher text, the working mode indication, the NAS MAC, the MAC-I, the first length, the second length, the key indicator, and the terminal capability indication can each be one or more bits.

[0186] In some embodiments, the first message comprises the working mode indication; wherein the working mode indication is used to indicate that the working mode is: confidentiality protection and integrity protection, or integrity protection, or confidentiality protection.

[0187] For example, when the working mode indication is of a first value, it is used to indicate unified confidentiality protection and integrity protection; or when the working mode indication is of a second value, it is used to indicate separate confidentiality protection and integrity protection; or when the working mode indication is of a third value, it is used to indicate integrity protection; or when the working mode indication is of a fourth value, it is used to indicate confidentiality protection.

[0188] For example, when the working mode indication is of a first value, it is used to indicate confidentiality protection and integrity protection; or when the working mode indication is of a third value, it is used to indicate integrity protection; or when the working mode indication is of a fourth value, it is used to indicate confidentiality protection.

[0189] In some embodiments, when the first message does not comprise the working mode indication, it is used to indicate that the working mode is confidentiality protection and integrity protection.

[0190] For example, when the first message does not comprise the working mode indication, the terminal determines that the working mode of the AE algorithm is confidentiality protection and integrity protection; for example, it can be considered as unified confidentiality protection and integrity protection.

[0191] In some embodiments, when the first message does not comprise the working mode indication but comprises the algorithm identification, the algorithm identification is also used to indicate the working mode.

[0192] Optionally, the algorithm identification is used by the terminal to determine the working mode of the AE algorithm. Optionally, the terminal determines the working mode of the AE algorithm based on the algorithm identification.

[0193] Optionally, the algorithm identity comprises at least one of: the first algorithm identity, the second algorithm identity, and / or the third algorithm identity; the first algorithm identity, the second algorithm identity, and the third algorithm identity each comprises at least one of: the first algorithm indication, the second algorithm indication, the third algorithm indication, the fourth algorithm indication, and the fifth algorithm indication.

[0194] Optionally, the first algorithm indication is used to indicate that the working mode is integrity protection. For example, the first algorithm indication of the first algorithm identity is used to indicate the working mode of integrity protection based on the Snow 5G AE algorithm.

[0195] Optionally, the second algorithm indication is used to indicate that the working mode is confidentiality protection. For example, the second algorithm indication of the second algorithm identity is used to indicate the working mode of confidentiality protection based on the AES-256 AE algorithm.

[0196] Optionally, the third algorithm indication is used to indicate that the working mode is confidentiality protection and integrity protection. For example, the third algorithm indication of the third algorithm identity is used to indicate the working mode of confidentiality protection and integrity protection based on the ZUC-256 AE algorithm.

[0197] Optionally, the fourth algorithm indication is used to indicate that the working mode is no integrity protection. For example, the fourth algorithm indication of the first algorithm identity is used to indicate the working mode of no integrity protection based on the Snow 5G AE algorithm.

[0198] Optionally, the fifth algorithm indication is used to indicate that the working mode is no confidentiality protection. For example, the fifth algorithm indication of the second algorithm identity is used to indicate the working mode of no confidentiality protection based on the AES-256 AE algorithm.

[0199] Optionally, the first algorithm indication, the second algorithm indication, the third algorithm indication, the fourth algorithm indication, and the fifth algorithm indication each can be one or more bits.

[0200] Optionally, the names of the first algorithm indication, the second algorithm indication, the third algorithm indication, the fourth algorithm indication, and the fifth algorithm indication are not limited.

[0201] Optionally, the terminal receives the first message, determines that the first message includes the algorithm identifier but does not include the working mode indication; and determines the working mode of the AE algorithm based on the algorithm identifier. For example, the terminal determines that the working mode of the AE algorithm is integrity protection of the Snow 5G-based AE algorithm if the terminal determines that the first message does not include the working mode indication but includes the first algorithm identifier, and the first algorithm identifier included in the first message is the first algorithm indication. For another example, the terminal determines that the working mode of the AE algorithm is confidentiality protection and integrity protection of the AES-256-based AE algorithm if the terminal determines that the first message does not include the working mode indication but includes the second algorithm identifier, and the second algorithm identifier included in the first message is the second algorithm indication.

[0202] In some embodiments, the network device is a first network element; and the first message includes at least one of the following: a random number, a cipher text, an algorithm identifier, a working mode indication, a NAS MAC, a first length, a key indicator, and terminal capability information. Optionally, the first network element can be an AMF.

[0203] Optionally, the working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm includes at least one of the following: a key indicator, an algorithm identifier, a NAS MAC, a first length, a random number, and a working mode indication.

[0204] Optionally, the working mode is confidentiality protection and integrity protection, and the associated data of the AE algorithm includes at least one of the following: a key indicator, an algorithm identifier, a NAS MAC, a first length, a random number, and a working mode indication.

[0205] Optionally, the working mode is separate confidentiality protection and integrity protection, and the first message does not include a cipher text. Here, the first message is sent by the first network element.

[0206] Optionally, the working mode is integrity protection, and the first message does not include a cipher text. Here, the first message is sent by the first network element.

[0207] Optionally, the first message includes a random number, and the random number is used by the terminal to determine an expected NAS MAC. For example, the terminal does not generate the expected NAS MAC based on the random number if the terminal determines that the first message does not include the random number. For example, the terminal determines the expected NAS MAC based on the random number if the terminal determines that the first message includes the random number.

[0208] In some embodiments, the network device is an access network device; and the first message includes at least one of the following: a random number, a cipher text, an algorithm identifier, a working mode indication, a MAC-I, a second length, a key indicator, and terminal capability information.

[0209] Optionally, the algorithm identifier is used to indicate the RRC message related AE algorithm or to indicate the UP message related AE algorithm.

[0210] For example, the algorithm identifier is of a first value, used to indicate the RRC message related AE algorithm; or the algorithm identifier is of a second value, used to indicate the UP message related AE algorithm.

[0211] Optionally, the working mode indication is used to indicate the RRC message related working mode or to indicate the UP message related working mode.

[0212] For example, the working mode indication is of a first value, used to indicate the RRC message related working mode; or the working mode indication is of a second value, used to indicate the UP message related working mode.

[0213] Optionally, the working mode is unified confidentiality protection and integrity protection, and the association data of the AE algorithm includes at least one of the following: the key indicator, the algorithm identifier, the MAC-I, the second length, the random number, and the working mode indication.

[0214] Optionally, the working mode is confidentiality protection and integrity protection, and the association data of the AE algorithm includes at least one of the following: the key indicator, the algorithm identifier, the MAC-I, the second length, the random number, and the working mode indication.

[0215] Optionally, the working mode is separate confidentiality protection and integrity protection, and the first message does not include the cipher text. Here, the first message is sent by the access network device.

[0216] Optionally, the working mode is integrity protection, and the first message does not include the cipher text. Here, the first message is sent by the access network device.

[0217] Optionally, the first message includes the random number, and the random number is used by the terminal to determine the expected MAC-I. For example, the terminal determines that the first message does not include the random number, and the terminal can not generate the expected MAC-I based on the random number. For example, the terminal determines that the first message includes the random number, and the terminal determines the expected MAC-I based on the random number.

[0218] In some embodiments, the name of the first message is not limited, which is, for example, the AE algorithm indication information or the AE algorithm negotiation information or the NAS security mode command (SMC) message or the AS SMC message.

[0219] In step S2103, the terminal performs the first operation.

[0220] In some embodiments, the terminal performs a first operation based on the first message.

[0221] Optionally, performing the first operation comprises at least one of determining the working mode, determining the associated data, determining the rejection message, and performing a security related processing on the first message.

[0222] Optionally, the terminal determines the working mode of the AE algorithm according to the working mode indication included in the first message based on the first message including the working mode indication.

[0223] Optionally, the terminal determines the working mode as confidentiality protection and integrity protection based on the first message not including the working mode indication.

[0224] Optionally, the terminal determines the working mode according to the algorithm identification based on the first message not including the working mode indication but including the algorithm identification.

[0225] Optionally, the terminal determines the associated data of the AE algorithm comprises at least one of the key indicator, the algorithm identification, the NAS MAC, the first length, the random number, and the working mode indication based on the working mode being unified confidentiality protection and integrity protection.

[0226] Optionally, the terminal determines the associated data of the AE algorithm comprises at least one of the key indicator, the algorithm identification, the NAS MAC, the first length, the random number, and the working mode indication based on the working mode being confidentiality protection and integrity protection.

[0227] Optionally, the terminal determines the associated data of the AE algorithm comprises at least one of the key indicator, the algorithm identification, the MAC-I, the second length, the random number, and the working mode indication based on the working mode being unified confidentiality protection and integrity protection.

[0228] Optionally, the terminal determines the associated data of the AE algorithm comprises at least one of the key indicator, the algorithm identification, the MAC-I, the second length, the random number, and the working mode indication based on the working mode being confidentiality protection and integrity protection.

[0229] Optionally, the terminal determines that the first message does not include the cipher text based on the working mode being separate confidentiality protection and integrity protection.

[0230] Optionally, the terminal determines that the first message does not include the cipher text based on the working mode being integrity protection.

[0231] Optionally, the terminal determines to use the random number to determine the expected NAS MAC or the expected MAC-I based on the first message including the random number.

[0232] Optionally, the terminal determines the NAS MAC or the MAC-I used for the security related processing of the terminal based on the random number.

[0233] Optionally, the terminal determines the reject message based on that the terminal capability indication stored in the terminal is different from the terminal capability indication in the first message. Optionally, the reject message is used to reject the first message.

[0234] Optionally, the terminal determines the reject message based on that the length of the received NAS MAC is different from the first length.

[0235] Optionally, the terminal determines the reject message based on that the length of the received MAC-I is different from the second length.

[0236] Optionally, the reject message is used to reject the security related processing of the first message, i.e. to reject the confidentiality related processing and the integrity related processing of the first message.

[0237] In some embodiments, the terminal performs the security related processing of the first message. For example, the terminal performs the integrity verification of the first message.

[0238] In some optional embodiments, the terminal sends a reject message to the first network element or sends a reject message to the access network device based on that the stored terminal capability indication is different from the terminal capability indication in the first message.

[0239] In some optional embodiments, the terminal sends a reject message to the first network element based on that the length of the received NAS MAC is different from the first length.

[0240] In some optional embodiments, the terminal sends a reject message to the access network device based on that the length of the received MAC-I is different from the second length.

[0241] At step S2104, the terminal sends a second message to the network device.

[0242] In some embodiments, the network device receives the second message sent by the terminal.

[0243] In some embodiments, the second message is used to indicate that the security related processing with the AE algorithm in the working mode is successful. For example, the second message is used to indicate that the integrity check with the AE algorithm in the working mode is successful.

[0244] In some embodiments, the name of the second message is not limited, which is, for example, the AE algorithm completion information or the NAS security mode complete (Security Mode Complete) message or the AS security mode complete message.

[0245] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and the terms "information," "message," "signal," "signaling," "report," "configuration," "indication," "instruction," "command," "channel," "parameter," "domain," "field," "symbol," "symbol," "codebook," "codeword," "codepoint," "bit," "data," "program," "chip," and the like can be replaced with each other.

[0246] In some embodiments, "acquire," "obtain," "get," "receive," "transmit," "bidirectional transmission," "send and / or receive," and the like can be replaced with each other, and can be interpreted as various meanings such as receiving from another subject, acquiring from a protocol, acquiring from a higher layer, obtaining by processing oneself, autonomously implementing, and the like.

[0247] In some embodiments, the terms "send," "transmit," "report," "issue," "transmit," "bidirectional transmission," "send and / or receive," and the like can be replaced with each other.

[0248] In some embodiments, the terms "certain," "preset," "pre-set," "set," "indicated," "a certain," "any," "first," and the like can be replaced with each other, and "certain A," "preset A," "pre-set A," "set A," "indicated A," "a certain A," "any A," "first A" can be interpreted as A specified in advance in a protocol and the like, can be interpreted as A obtained by setting, configuring, or indicating, and the like, can be interpreted as certain A, a certain A, any A, or first A, and the like, but are not limited thereto.

[0249] In some embodiments, determination or judgment can be performed by a value represented by 1 bit (0 or 1), can be performed by a true or false value (Boolean value) represented by true or false, can be performed by comparison of a numerical value (for example, comparison with a predetermined value), but is not limited thereto.

[0250] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2101 to S2104. For example, step S2101 can be implemented as an independent embodiment; step S2102 can be implemented as an independent embodiment; step S2103 can be implemented as an independent embodiment; step S2104 can be implemented as an independent embodiment; a combination of step S2101 and step S2102 can be implemented as an independent embodiment; a combination of step S2102 and step S2103 can be implemented as an independent embodiment; a combination of step S2103 and step S2104 can be implemented as an independent embodiment; a combination of step S2101 and step S2103 can be implemented as an independent embodiment; a combination of step S2101 and step S2102 and step S2103 can be implemented as an independent embodiment; a combination of step S2102 and step S2103 and step S2104 can be implemented as an independent embodiment; and a combination of steps S2101 to S2104 can be implemented as an independent embodiment.

[0251] In some embodiments, steps S2101, S2103 and S2104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0252] In some embodiments, steps S2102, S2103 and S2104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0253] In some embodiments, steps S2101 and S2104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0254] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0255] FIG. 3A is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiments of the present disclosure relate to an information processing method, which is performed by a network device, and the above method comprises:

[0256] In step S3101, policy information is acquired. Optionally, the network device is an access network device.

[0257] For optional implementation of step S3101, reference can be made to the optional implementation of step S2101 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here again.

[0258] In some embodiments, the access network device receives the policy information sent by the second network element, but is not limited thereto, and can also receive the policy information sent by other subjects.

[0259] In some embodiments, the access network device acquires the protocol-specified policy information.

[0260] In some embodiments, the access network device acquires the policy information from upper layer(s).

[0261] In some embodiments, the access network device processes to obtain the policy information.

[0262] In some embodiments, step S3101 is omitted, and the terminal autonomously implements the function indicated by the policy information, or the above function is default or default.

[0263] Step S3102, sending a first message. Optionally, the network device is an access network device or a core network device. Optionally, the core network device is the first network element.

[0264] Optional implementation of step S3102 can refer to optional implementation of step S2102 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0265] In some embodiments, the network device can send the first message to the terminal, but is not limited thereto, and can also send the first message to other subjects.

[0266] Step S3103, acquiring a second message. Optionally, the network device is an access network device or a core network device. Optionally, the core network device is the first network element.

[0267] Optional implementation of step S3103 can refer to optional implementation of step S2104 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0268] In some embodiments, the network device receives the second message sent by the terminal, but is not limited thereto, and can also receive the second message sent by other subjects.

[0269] In some embodiments, the network device acquires the protocol-specified second message.

[0270] In some embodiments, the network device acquires the second message from upper layer(s).

[0271] In some embodiments, the network device processes to obtain the second message.

[0272] In some embodiments, step S3103 is omitted, and the terminal autonomously implements the function indicated by the second message, or the above function is default or default.

[0273] The information processing method related to the embodiments of the present disclosure can include at least one of steps S3101 to S3103. For example, step S3101 can be implemented as an independent embodiment; step S3102 can be implemented as an independent embodiment; step S3103 can be implemented as an independent embodiment; a combination of steps S3101 and S3102 can be implemented as an independent embodiment; a combination of steps S3102 and S3103 can be implemented as an independent embodiment; and a combination of steps S3101 to S3103 can be implemented as an independent embodiment.

[0274] In some embodiments, step S3101 can be optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0275] In some embodiments, steps S3102 and S3103 can be optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0276] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0277] FIG. 3B is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to an information processing method, which is performed by a network device, and the above method includes:

[0278] Step S3201, sending a first message to a terminal, wherein the first message includes an algorithm identifier; the algorithm identifier is used by the terminal to determine an AE algorithm for security-related processing.

[0279] The optional implementation of step S3201 can refer to the optional implementation of step S2102 in FIG. 2, or the optional implementation of step S3102 in FIG. 3A, and other related parts in the embodiments related to FIG. 2 and FIG. 3A, which will not be repeated here.

[0280] In some embodiments, the AE algorithm is an AEAD algorithm.

[0281] In some embodiments, the first message is further used to determine a working mode of the AE algorithm; the working mode is one of the following: confidentiality protection and integrity protection; integrity protection; and confidentiality protection.

[0282] In some embodiments, the confidentiality protection and integrity protection comprises one of: unified confidentiality protection and integrity protection; separate confidentiality protection and integrity protection.

[0283] In some embodiments, the first message comprises an operation mode indication; wherein the operation mode indication is used to indicate that the operation mode is: confidentiality protection and integrity protection, or integrity protection, or confidentiality protection.

[0284] In some embodiments, when the first message does not comprise the operation mode indication, the first message is used to indicate that the operation mode is confidentiality protection and integrity protection; or when the first message does not comprise the operation mode indication but comprises the algorithm identification, the algorithm identification is further used to indicate the operation mode.

[0285] In some embodiments, the algorithm identification comprises at least one of: a first algorithm identification, a second algorithm identification, and / or a third algorithm identification; the first algorithm identification, the second algorithm identification, and the third algorithm identification each comprises at least one of: a first algorithm indication, used to indicate that the operation mode is integrity protection; a second algorithm indication, used to indicate that the operation mode is confidentiality protection; a third algorithm indication, used to indicate that the operation mode is confidentiality protection and integrity protection; a fourth algorithm indication, used to indicate that the operation mode is no integrity protection; and a fifth algorithm indication, used to indicate that the operation mode is no confidentiality protection.

[0286] In some embodiments, the algorithm identification comprises at least one of: a first algorithm identification, used to indicate a Snow 5G based AE algorithm; a second algorithm identification, used to indicate an AES-256 based AE algorithm; and a third algorithm identification, used to indicate a ZUC-256 based AE algorithm.

[0287] In some embodiments, the first message further comprises at least one of: a random number; a cipher text; an operation mode indication, used to indicate the operation mode; a NAS MAC; a MAC-I; a first length, used to indicate the length of the NAS MAC; a second length, used to indicate the length of the MAC-I; a key indicator, used to indicate an intermediate key; a terminal capability indication, used to indicate the algorithm identification of the AE algorithm supported by the terminal.

[0288] In some embodiments, the network device is a first network element; the first message comprises at least one of: a random number; a cipher text; an algorithm identification; an operation mode indication; a NAS MAC; a first length; a key indicator; and terminal capability information.

[0289] In some embodiments, the network device is an access network device; the first message comprises at least one of the following: a random number; cipher text; an algorithm identifier; an operation mode indication; a MAC-I; a second length; a key indicator; and terminal capability information.

[0290] In some embodiments, the algorithm identifier is used to indicate an AE algorithm related to an RRC message or to indicate an AE algorithm related to a UP message; or the operation mode indication is used to indicate an operation mode related to an RRC message or to indicate an operation mode related to a UP message.

[0291] In some embodiments, the method further comprises: obtaining policy information from the second network element; wherein the policy information comprises one of the following: a first policy indication used to indicate that authentication encryption or partial encryption must be used; a second policy indication used to indicate that authentication encryption or partial encryption is preferred to be used; and a third policy indication used to indicate that authentication encryption or partial encryption does not need to be used.

[0292] In some embodiments, when the operation mode is unified confidentiality protection and integrity protection, the associated data of the AE algorithm comprises at least one of the following: a key indicator, an algorithm identifier, a NAS MAC, a first length, a random number, and an operation mode indication; or when the operation mode is unified confidentiality protection and integrity protection, the associated data of the AE algorithm comprises at least one of the following: a key indicator, an algorithm identifier, a MAC-I, a second length, a random number, and an operation mode indication.

[0293] In some embodiments, when the operation mode is separate confidentiality protection and integrity protection, the cipher text is not included in the first message; or when the operation mode is integrity protection, the cipher text is not included in the first message.

[0294] In some embodiments, the first message comprises a random number, and the random number is used by the terminal to determine an expected NAS MAC or an expected MAC-I.

[0295] The above embodiments can be implemented independently or in combination with each other, and optional implementation manners can refer to the optional implementation manners of the steps of FIG. 2 and FIG. 3A, which are not described herein again.

[0296] FIG. 4A is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 4A, the embodiment of the present disclosure relates to an information processing method, which is performed by a terminal, and the above method comprises:

[0297] In step S4101, a first message is obtained.

[0298] The optional implementation of step S4101 can refer to the optional implementation of step S2102 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0299] In some embodiments, the terminal receives the first message sent by the network device, but is not limited thereto, and can also receive the first message sent by other subjects.

[0300] In some embodiments, the terminal acquires the first message specified by the protocol.

[0301] In some embodiments, the terminal acquires the first message from the upper layer(s).

[0302] In some embodiments, the terminal processes to obtain the first message.

[0303] In some embodiments, step S4101 is omitted, and the terminal autonomously implements the function indicated by the first message, or the above function is default or default.

[0304] Step S4102, performing the first operation. Optionally, the terminal performs the first operation based on the first message.

[0305] The optional implementation of step S4102 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0306] Step S4103, sending the second message.

[0307] The optional implementation of step S4103 can refer to the optional implementation of step S2104 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0308] In some embodiments, the terminal can send the second message to the network device, but is not limited thereto, and can also send the second message to other subjects.

[0309] The information processing method involved in the embodiments of the present disclosure can include at least one of steps S4101 to S4103. For example, step S4101 can be implemented as an independent embodiment; step S4102 can be implemented as an independent embodiment; step S4103 can be implemented as an independent embodiment; the combination of step S4101 and step S4102 can be implemented as an independent embodiment; the combination of step S4102 and step S4103 can be implemented as an independent embodiment; and the combination of steps S4101 to S4103 can be implemented as an independent embodiment.

[0310] In some embodiments, step S4102 and step S4103 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0311] In some embodiments, step S4103 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0312] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps or subsequent steps.

[0313] FIG. 4B is a flow diagram illustrating a method of information processing, according to an embodiment of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to a method of information processing, which is performed by a network device, and the above method comprises:

[0314] Step S4201, receiving a first message sent by a network device, wherein the first message comprises an algorithm identifier; the algorithm identifier is used by a terminal to determine an AE algorithm for security-related processing.

[0315] The optional implementation of step S4201 can refer to the optional implementation of step S2102 in FIG. 2, or the optional implementation of step S4101 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2, FIG. 4A, which will not be repeated here.

[0316] In some embodiments, the AE algorithm is AEAD.

[0317] In some embodiments, the first message is further used to determine a working mode of the AE algorithm; the working mode is one of the following: confidentiality protection and integrity protection; integrity protection; and confidentiality protection.

[0318] In some embodiments, the confidentiality protection and the integrity protection comprise one of the following: unified confidentiality protection and integrity protection; separate confidentiality protection and integrity protection.

[0319] In some embodiments, the first message comprises a working mode indication; wherein the working mode indication is used to indicate that the working mode is: confidentiality protection and integrity protection, or integrity protection, or confidentiality protection.

[0320] In some embodiments, the method further comprises: determining that the working mode is confidentiality protection and integrity protection based on the first message not comprising the working mode indication; or determining the working mode according to the algorithm identifier based on the first message not comprising the working mode indication but comprising the algorithm identifier.

[0321] In some embodiments, the algorithm identity comprises at least one of: the first algorithm identity, the second algorithm identity, and / or the third algorithm identity; the first algorithm identity, the second algorithm identity, and the third algorithm identity each comprises at least one of: a first algorithm indication indicating that the operation mode is integrity protection; a second algorithm indication indicating that the operation mode is confidentiality protection; a third algorithm indication indicating that the operation mode is confidentiality protection and integrity protection; a fourth algorithm indication indicating that the operation mode is no integrity protection; and a fifth algorithm indication indicating that the operation mode is no confidentiality protection.

[0322] In some embodiments, the algorithm identity comprises at least one of: a first algorithm identity indicating a Snow 5G based AE algorithm; a second algorithm identity indicating an AES-256 based AE algorithm; and a third algorithm identity indicating a ZUC-256 based AE algorithm.

[0323] In some embodiments, the first message comprises at least one of: a random number; a cipher text; an operation mode indication indicating an operation mode; a NAS MAC; a MAC-I; a first length indicating a length of the NAS MAC; a second length indicating a length of the MAC-I; a key indicator indicating an intermediate key; and a terminal capability indication indicating algorithm identities of AE algorithms supported by the terminal.

[0324] In some embodiments, the network device is a first network element; and the first message comprises at least one of: a random number; a cipher text; an algorithm identity; an operation mode indication; a NAS MAC; a first length; a key indicator; and terminal capability information.

[0325] In some embodiments, the network device is an access network device; and the first message comprises at least one of: a random number; a cipher text; an algorithm identity; an operation mode indication; a MAC-I; a second length; a key indicator; and terminal capability information.

[0326] In some embodiments, the algorithm identity indicates an AE algorithm related to RRC messages or an AE algorithm related to UP messages; or the operation mode indication indicates an operation mode related to RRC messages or an operation mode related to UP messages.

[0327] In some embodiments, the working mode is unified confidentiality protection and integrity protection, the association data of the AE algorithm includes at least one of the following: a key indicator, an algorithm identifier, a NAS MAC, a first length, a random number, and a working mode indicator; or, the working mode is unified confidentiality protection and integrity protection, the association data of the AE algorithm includes at least one of the following: a key indicator, an algorithm identifier, a MAC-I, a second length, a random number, and a working mode indicator.

[0328] In some embodiments, the working mode is separate confidentiality protection and integrity protection, and the first message does not include cipher text; or, the working mode is integrity protection, and the first message does not include cipher text.

[0329] In some embodiments, the first message includes a random number, and the random number is used to determine an expected NAS MAC or an expected MAC-I by the terminal. Optionally, the terminal determines the expected NAS MAC or the expected MAC-I based on the random number if the first message includes the random number.

[0330] In some embodiments, the method further includes at least one of the following: sending a rejection message to the first network element or sending a rejection message to the access network device based on the terminal capability indication stored by the terminal being different from the terminal capability indication in the first message; sending a rejection message to the first network element based on the length of the NAS MAC received by the terminal being different from the first length; and sending a rejection message to the access network device based on the length of the MAC-I received by the terminal being different from the second length.

[0331] The above embodiments can be implemented independently or in combination with each other, and optional implementation manners can refer to the optional implementation manners of the steps in FIG. 2 and FIG. 4A, which are not described herein again.

[0332] FIG. 5A is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 5A, the embodiment of the present disclosure relates to an information processing method, which is performed by a second network element, and the above method includes:

[0333] In step S5101, policy information is acquired.

[0334] In some embodiments, the second network element receives the policy information sent by the third network element, but is not limited thereto, and can also receive the policy information sent by other subjects.

[0335] In some embodiments, the second network element acquires the policy information specified by a protocol.

[0336] In some embodiments, the second network element acquires the policy information from an upper layer.

[0337] In some embodiments, the second network element processes to obtain the policy information.

[0338] In some embodiments, step S5101 is omitted, and the terminal autonomously implements the function indicated by the policy information, or the above function is default or default.

[0339] Optionally, the second network element is an SMF, and the third network element is a UDM.

[0340] Step S5102, sending policy information.

[0341] Optional implementation of step S5102 can refer to optional implementation of step S2101 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0342] In some embodiments, the second network element can send the policy information to the access network device, but is not limited thereto, and can also send the policy information to other subjects.

[0343] The information processing method involved in the embodiments of the present disclosure can include at least one of steps S5101 to S5102. For example, step S5101 can be implemented as an independent embodiment; step S5102 can be implemented as an independent embodiment; and the combination of step S5101 and step S5102 can be implemented as an independent embodiment.

[0344] In some embodiments, step S5102 can be optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0345] In some embodiments, step S5101 can be optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0346] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0347] FIG. 5B is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 5B, the embodiments of the present disclosure involve an information processing method, which is executed by a second network element, and the above method includes:

[0348] Step S5201, sending policy information.

[0349] Optional implementation of step S5201 can refer to optional implementation of step S2101 in FIG. 2, or optional implementation of step S5102 in FIG. 5A, and other associated parts in the embodiments involved in FIG. 2 and FIG. 5A, which will not be repeated here.

[0350] Optionally, the policy information comprises one of: a first policy indication indicating that authenticated encryption or partial encryption must be used (Require); a second policy indication indicating that authenticated encryption or partial encryption is preferred (Prefer); and a third policy indication indicating that authenticated encryption or partial encryption is not needed (Not Need).

[0351] The optional implementation of step S5201 can refer to the optional implementation of step S5102 in FIG. 5A and other associated parts in the embodiments involved in FIG. 5A, which will not be repeated here.

[0352] In some embodiments, the method further comprises: obtaining the policy information from a third network element.

[0353] In some embodiments, the first network element is an AMF; and / or, the second network element is an SMF; and / or, the third network element is a UDM.

[0354] The above embodiments can be implemented independently or in combination with each other, and the optional implementation can refer to the optional implementation of steps in FIG. 2 and FIG. 5A, which will not be repeated here.

[0355] FIG. 6 is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 6, the embodiment of the present disclosure relates to an information processing method for an information processing system 100, and the above method comprises:

[0356] In step S6101, the network device sends a first message to the terminal.

[0357] The optional implementation of step S6101 can refer to the optional implementation of step S2102 in FIG. 2, step S3102 in FIG. 3, step S4101 in FIG. 4A, and other associated parts in the embodiments involved in FIG. 2, FIG. 3, and FIG. 4A, which will not be repeated here.

[0358] In step S6102, the terminal sends a second message to the network device.

[0359] The optional implementation of step S6102 can refer to the optional implementation of step S2104 in FIG. 2, step S3103 in FIG. 3, step S4103 in FIG. 4A, and other associated parts in the embodiments involved in FIG. 2, FIG. 3, and FIG. 4A, which will not be repeated here.

[0360] In some embodiments, the above method can include the method described in the above communication system side, network device side, terminal side, and / or second network element side embodiments, which will not be repeated here.

[0361] Embodiments of the present disclosure relate to an information processing method, which comprises:

[0362] In some embodiments, as shown in FIG. 7A, details of the AEAD algorithm negotiation in the communication system are defined. Among them, the first part: NAS SMC based AEAD algorithm negotiation mechanism; the second part: AS SMC (i.e. negotiation related to RRC and UP message protection mechanism) based AEAD algorithm negotiation mechanism; the third part: UP policy of partial encryption algorithm. Optionally, the access network device obtains the UP policy of the AEAD algorithm negotiation. Optionally, the UP policy can be a UP security policy. Optionally, the UE can be a terminal.

[0363] I. The first part: NAS SMC based AEAD algorithm negotiation mechanism.

[0364] FIG. 7B is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 7B, embodiments of the present disclosure relate to an information processing method, which comprises:

[0365] Step S7101, the AMF starts NAS integrity protection.

[0366] Optionally, the AMF activates the NAS integrity protection before sending the NAS security mode command message (NAS SMC).

[0367] Step S7102, the AMF sends the NAS SMC message to the UE.

[0368] Optionally, the NAS SMC message can include: UE security capabilities, selected AEAD algorithm based algorithm identity, AEAD algorithm based work mode (WorkMode), random number (Fresh), ciphertext, length of NAS MAC, and key (ngKSI) used to identify K AMF . Here, the ciphertext is determined by the network operator. The random number is used for integrity protection. The work mode is used to indicate the work mode based on the AEAD algorithm; for example, the AEAD algorithm is used for separate confidentiality and integrity protection, the AEAD algorithm is used for simultaneous (or unified) encryption and integrity protection, or the AEAD algorithm is used for integrity protection. The UE security capabilities can be the terminal capability information in the previous embodiments.

[0369] Optionally, if the operation mode is AEAD algorithm based for unified confidentiality and integrity protection, the ngKSI, the algorithm identity based on the AEAD algorithm, the length of the NAS MAC, the FRESH and / or the operation mode are considered as the association data based on the AEAD algorithm.

[0370] Optionally, if the operation mode is AEAD algorithm based for separate confidentiality and integrity calculation, or the operation mode is integrity protection, no cipher text is included in the NAS SMC message.

[0371] Optionally, if the K AMF (i.e. the key indicating the AMF) indicated by the ngKSI in the NAS SMC message, the NAS MAC message shall be integrity protected (but not confidentiality protected) using the NAS integrity key.

[0372] Step S7103, the AMF starts uplink decryption.

[0373] Optionally, the AMF activates the NAS uplink decryption after sending the NAS SMC message.

[0374] Step S7104, the UE verifies the NAS SMC message.

[0375] Optionally, the UE verifies the NAS MAC integrity, and if successful, starts uplink encryption, downlink decryption and / or integrity protection.

[0376] Optionally, the UE will verify the NAS SMC, which includes at least one of the following:

[0377] If the UE security capabilities checked by the AMF match the UE security capabilities stored in the UE, it is ensured that these UE security capabilities have not been modified by an attacker, and the indicated NAS integrity protection and the NAS integrity key based on the K AMF indicated by the ngKSI to verify the integrity protection.

[0378] If the length of the NAS SMC is not equal to the length of the NAS MAC included in the NAS SMC message, the UE shall reply with a NAS security mode reject message (NAS SMR).

[0379] If the random number is included, the random number is used to determine the NAS MAC.

[0380] If the integrity verification of the NAS SMC message is successful, the UE will start the NAS integrity protection and the confidentiality protection using the security context indicated by the ngKSI.

[0381] Step S7105, the UE sends a NAS security mode complete message protected by confidentiality and integrity to the AMF.

[0382] Optionally, the NAS security mode complete message is further used to indicate that the AMF should use the key and algorithm indicated in the NAS SMC message to protect the NAS security mode complete message by confidentiality and integrity. After receiving the NAS security mode complete message, the AMF starts the NAS downlink encryption with the security context.

[0383] Step S7106, the AMF starts the NAS downlink encryption.

[0384] II. Second part: AEAD algorithm negotiation mechanism based on AS SMC.

[0385] FIG. 7C is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 7C, the present embodiment of the present disclosure relates to an information processing method, and the method comprises:

[0386] The AS SMC procedure is used for RRC and UP security algorithm negotiation and RRC security activation. For a base station, the SMC procedure includes a round-trip message between the base station and the UE; that is, it includes: the base station sends an AS SMC to the UE, and the UE sends an AS security mode complete message to the base station in reply. Optionally, the base station can be a gNB or an ng-eNB.

[0387] The AS SMC message sent from the base station (such as a gNB or an ng-eNB) to the UE should contain the selected RRC and UP confidentiality and integrity algorithms (i.e. RRC and UP confidentiality and integrity protection). This AS SMC should be integrity protected using the RRC integrity key based on the current key (K gNB ).

[0388] Step S7201, the base station starts RRC integrity protection or UP integrity protection.

[0389] Optionally, the AMF activates the RRC integrity protection or the UP integrity protection before sending the AS SMC.

[0390] Step S7202, the base station sends an AS SMC message to the UE.

[0391] Optionally, if an AEAD algorithm is selected for RRC security, the AS SMC message can include: the algorithm identifier of the RRC message related AEAD algorithm, the working mode of the RRC message related AEAD algorithm, the length of the cipher text (optional), the MAC-I and / or the length of the fresh random number. The random number is used for integrity protection. The cipher text is determined by the network operator.

[0392] Optionally, if the UP security selects the AEAD-based algorithm, the AS SMC message can include: the algorithm identity of the UP message related AEAD-based algorithm, the algorithm operation mode of the UP message related AEAD-based algorithm, the cipher text (optional), the length of the MAC-I and / or the fresh random number. The random number is used for integrity protection. The cipher text is determined by the network operator.

[0393] Optionally, if the UP policy indicates that partial encryption is mandatory or preferred, the base station can send the UE the UP related AEAD-based algorithm identity. The UP policy indication can be the policy information in the previous embodiment; the UP policy indication is obtained by the base station from the SMF.

[0394] Optionally, if the work mode (WorkMode) is the unified confidentiality and integrity protection based on the AEAD algorithm for RRC messages, the RRC related AEAD-based algorithm identity, the length of the MAC-I, the random number, the RRC related AEAD-based algorithm operation mode, the UP related AEAD-based algorithm identity (optional) and / or the UP related AEAD-based algorithm operation mode (optional) are all considered as the associated data of the AEAD algorithm.

[0395] Optionally, if the work mode is the separate confidentiality and integrity protection based on the AEAD algorithm for RRC messages, or the work mode is the integrity protection, the cipher text is not included in the AS SMC message.

[0396] Step S7203, the base station starts uplink encryption.

[0397] Optionally, the base station activates RRC downlink encryption or UP downlink encryption after sending the AS SMC.

[0398] Step S7204, the UE verifies the AS SMC message.

[0399] Optionally, the AS security mode complete message from the UE to the base station should be integrity protected using the selected RRC algorithm in the AS SMC message and the RRC integrity key based on the current K gNB .

[0400] If the length of the MAC-I is not equal to the length of the MAC-I contained in the AS SMC, the UE should reply with the AS security rejection message (AS Security Mode Reject message, AS SMR) or the unprotected security mode failure message.

[0401] If the random number is included, the random number is used to determine the MAC-I.

[0402] Optionally, RRC downlink encryption at the base station shall start after sending the AS security mode command message. RRC uplink deciphering at the gNB / ng-eNB shall start after receiving and successfully verifying the AS SMC message.

[0403] Step S7205, the UE sends a confidentiality and integrity protected NAS security mode complete message to the base station.

[0404] Optionally, RRC or UP uplink encryption at the UE shall start after sending the AS security mode command message. RRC or UP downlink deciphering at the UE shall start after receiving and successfully verifying the AS security mode command message.

[0405] Optionally, if any control over the AS security mode command in the UE is not successful, the UE shall reply with an unprotected security mode failure message.

[0406] Step S7206, the terminal starts uplink encryption. Optionally, the terminal starts RRC or UP uplink encryption.

[0407] Step S7207, the base station starts downlink deciphering. Optionally, the base station starts RRC or UP downlink deciphering.

[0408] III. Third Part: UP Policy of Partial Encryption Algorithm

[0409] In some embodiments, the user plane security enforcement information provides an access network device (e.g., a base station) with a user plane (UP) security policy for a PDU session.

[0410] Optionally, the UP policy indicates whether UP integrity protection is performed; wherein whether UP integrity protection is performed:

[0411] Mandatory: integrity protection is applied for all traffic on the PDU session;

[0412] Preferred: integrity protection is applied for all traffic on the PDU session;

[0413] Not needed: no integrity protection is used for the corresponding PDU session.

[0414] Optionally, the UP policy indicates whether UP confidentiality protection is performed; wherein whether UP confidentiality protection is performed:

[0415] Mandatory: confidentiality protection is applied for all traffic on the PDU session;

[0416] Preferred: confidentiality protection is applied for all traffic on the PDU session;

[0417] Not needed: No confidentiality protection is used for the PDU session.

[0418] Optionally, the UP policy indicates whether partial encryption is performed; and whether partial encryption is performed:

[0419] Mandatory: Partial encryption is used for all traffic on the PDU session.

[0420] Preferred: Partial encryption is used for all traffic on the PDU session.

[0421] Not needed: No partial encryption is used for the PDU session.

[0422] In some embodiments, the user plane security enforcement information applies to 3GPP access. Once the user plane security enforcement information is determined at PDU session establishment, the user plane security enforcement information applies for the lifetime of the PDU session.

[0423] In some embodiments, the SMF determines the user plane security enforcement information for the user plane of the PDU session at PDU session establishment based on: a subscribed UP policy (e.g., partial encryption related policy) that is part of the SM subscription information received from the UDM; and / or, a locally configured UP policy in the SMF according to (e.g., data network name (DNN) or Single Network Slice Selection Assistance Information (S-NSSAI)), used when the UDM does not provide UP policy information.

[0424] Four, optional solution one.

[0425] In some embodiments, if an AEAD-based algorithm identity is received without a working mode, the UE shall set the working mode of the AEAD-based algorithm identity to integrated encryption and integrity protection.

[0426] In some embodiments, if an AEAD-based algorithm identity is received without a working mode, the UE shall set the working mode of the AEAD-based algorithm identity to integrated encryption and integrity protection, i.e., both encryption and integrity protection are performed.

[0427] Five, optional solution two.

[0428] In some embodiments, the AMF or the access network device can also indicate the function of the AEAD algorithm to the UE by the algorithm identification as shown in Table 1 below.

[0429] Table 1

[0430] Optionally, 256-NCA1, 256-NCA2 and 256-NCA3 can be the first, second and third algorithm identification respectively in the previous embodiments. 256-NCIA1, 256-NCIA2 and 256-NCIA3 can be the first, second and third algorithm indication respectively of the first, second and third algorithm identification in the previous embodiments; 256-NCIA0 can be the fourth algorithm indication of the first, second and third algorithm identification in the previous embodiments; 256-NCEA1, 256-NCEA2 and 256-NCEA3 can be the second algorithm indication respectively of the first, second and third algorithm identification in the previous embodiments; 256-NCEA0 can be the fifth algorithm indication of the first, second and third algorithm identification in the previous embodiments; 256-NCIEA1, 256-NCIEA2 and 256-NCIEA3 can be the third algorithm indication respectively in the previous embodiments.

[0431] Six, negotiation mechanism based on AEAD algorithm.

[0432] Embodiment 1 (AMF):

[0433] In some embodiments, the AMF selects an AEAD algorithm based on the security algorithm of the NAS; the AMF sends the algorithm identification based on the AEAD, the working mode based on the AEAD algorithm, the random number (Fresh), the ciphertext (optional) and the length of the NAS MAC to the UE.

[0434] Optionally, the working mode is the working mode based on the AEAD algorithm; for example, the working mode based on the AEAD algorithm for separate confidentiality and integrity protection, the working mode based on the AEAD algorithm for unified confidentiality and integrity protection, or the working mode based on the AEAD algorithm for integrity protection.

[0435] Optionally, if the working mode is the working mode based on the AEAD algorithm for unified confidentiality and integrity protection, the ngKSI, the algorithm identification based on the AEAD algorithm, the length of the NAS MAC, the random number and / or the working mode are considered as the associated data of the AEAD algorithm.

[0436] Optionally, if the working mode is based on the AEAD algorithm for separate confidentiality and integrity protection, or based on the AEAD algorithm for integrity protection, the cipher text is not included in the NAS SMC message.

[0437] Optionally, the AMF can indicate its function by using the algorithm identity of the AEAD algorithm.

[0438] Embodiment 2 (UE side):

[0439] In some embodiments, if the length of the NAS SMC is not equal to the length of the NAS SMC included in the NAS SMC message, the UE shall reply with a NAS security mode reject message; or if the length of the AS SMC is not equal to the length of the AS SMC included in the AS SMC message, the UE shall reply with an AS security mode reject message or an unprotected security mode failure message.

[0440] Optionally, if the UE receives the random number, the UE generates the NAS MAC or the MAC-I using the random number. Here, the NAS MAC or the MAC-I can be the expected NAS MAC or the expected MAC-I in the previous embodiments.

[0441] Optionally, if the UE receives the algorithm identity based on the AEAD algorithm without receiving the working mode, the UE shall set the working mode of the algorithm identity based on the AEAD algorithm to unified confidentiality and integrity protection.

[0442] Embodiment 3 (access network device):

[0443] In some embodiments, if the access network device receives the algorithm identity based on the AEAD algorithm without receiving the working mode, the UE shall set the working mode of the algorithm identity based on the AEAD algorithm to integrated encryption and integrity protection.

[0444] Optionally, if the AEAD algorithm based on the UP security is selected, the NAS SMC message further includes the algorithm identity based on the AEAD algorithm of the UP message and the working mode based on the AEAD algorithm related to the UP message.

[0445] Optionally, if the UP policy indicates that partial encryption is mandatory or preferred, the base station sends the UE the algorithm identity based on the AEAD related to the UP message.

[0446] Optionally, if the operation mode is unified confidentiality and integrity protection based on AEAD algorithms for RRC messages, the RRC message related AEAD algorithm based algorithm identity, length of MAC-I, nonce, RRC message related AEAD algorithm based operation mode, UP message related AEAD algorithm based algorithm identity (optional) and / or UP message related AEAD algorithm based operation mode (optional) are considered as associated data for the AEAD based algorithm.

[0447] Optionally, if the operation mode is separate confidentiality protection and integrity protection based on AEAD algorithms for RRC messages, no cipher text is included in the AS SMC message.

[0448] Optionally, if the UP policy indicates that partial encryption is needed or preferred, the gNB can send the UP related AEAD based algorithm identity to the UE.

[0449] Optionally, the access network equipment can indicate their functionality with the algorithm identity of the AEAD algorithm.

[0450] Optionally, the access network equipment should be able to obtain the UP policy of the AEAD algorithm from the SMF. The SMF receives the UP policy related to the AEAD algorithm from the UDM. The UP policy includes whether partial encryption is performed; the whether partial encryption is performed includes one of the following: necessary: partial encryption is used for all traffic on the PDU session; preferred: partial encryption is used for all traffic on the PDU session; not needed: no PDU session for which AEAD is not applicable to partial encryption.

[0451] Embodiment 4 (SMF):

[0452] In some implementations, the SMF receives the partial encryption related UP policy from the UDM.

[0453] In some implementations, the SMF receives the authentication encryption related UP policy from the UDM.

[0454] Optionally, the UP policy includes whether partial encryption is performed; the whether partial encryption is performed includes one of the following: necessary: partial encryption is used for all traffic on the PDU session; preferred: partial encryption is used for all traffic on the PDU session; not needed: no PDU session for which AEAD is not used.

[0455] Optionally, the UP policy includes whether authentication encryption is performed; the whether authentication encryption is performed includes one of the following: necessary: authentication encryption (AE) is used for all traffic on the PDU session; preferred: authentication encryption is used for all traffic on the PDU session; not needed: no PDU session for which authentication encryption is not used.

[0456] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.

[0457] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device comprising units or modules for implementing the steps performed by a terminal in any of the above methods. For another example, another device is proposed, comprising units or modules for implementing the steps performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0458] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of them can be integrated into one physical entity, or can be physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or the functions of each unit or module of the device, wherein the processor is, for example, a general processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by designing the hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by designing the logical relationship of elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules can be implemented in the form of processor calling software, and the remaining part can be implemented in the form of hardware circuit.

[0459] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0460] FIG. 8A is a structural schematic diagram of a network device 8100 according to an embodiment of the present disclosure. As shown in FIG. 8A, the network device 8100 includes a first transceiver module 8101. In some embodiments, the first transceiver module 8101 is configured to send a first message. Optionally, the first transceiver module 8101 is configured to perform at least one of the sending and / or receiving steps (for example, steps S2101 and / or S2102 and / or S2104, but not limited thereto) performed by the network device 8100 in any of the above methods. Details are not described herein again.

[0461] FIG. 8B is a structural schematic diagram of the terminal 8200 according to an embodiment of the present disclosure. As shown in FIG. 8B, the terminal 8200 includes a second transceiver module 8201 and a processing module 8202. In some embodiments, the second transceiver module 8201 described above is configured to receive the first message. Optionally, the transceiver module 8201 is configured to perform at least one of the sending and / or receiving steps (for example, the steps S2101 and / or the steps S2102 and / or the steps S2104, but are not limited thereto) performed by the terminal 8200 in any of the methods described above, details of which are not described herein again. In some embodiments, the processing module 8202 is configured to determine the second network element. The processing module 8202 described above is configured to perform at least one of the processing steps (for example, the steps S2102, but are not limited thereto) performed by the first network element in any of the methods described above, details of which are not described herein again.

[0462] FIG. 8C is a structural schematic diagram of the second network element 8300 according to an embodiment of the present disclosure. As shown in FIG. 8C, the second network element 8300 includes a third transceiver module 8301. In some embodiments, the third transceiver module 8301 described above is configured to receive the policy information sent by the third network element, and send the policy information to the access network device. Optionally, the third transceiver module 8301 described above is configured to perform at least one of the sending and / or receiving steps (for example, the steps S2101, but are not limited thereto) performed by the second network element 8300 in any of the methods described above, details of which are not described herein again.

[0463] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver. For example, the first transceiver module described above includes a first sending module and / or a first receiving module. For example, the second transceiver module described above includes a second sending module and / or a second receiving module.

[0464] In some embodiments, the processing module can be a module or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module. Optionally, the processing module can be mutually replaced with a processor.

[0465] FIG. 9A is a structural schematic diagram of a communication device 9100 according to an embodiment of the present disclosure. The communication device 9100 can be a network device (for example, an access network device, a core network device, etc.), a terminal, etc., can be a chip, a chip system, or a processor supporting the network device to implement any of the methods described above, or can be a chip, a chip system, or a processor supporting the terminal to implement any of the methods described above. The communication device 9100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0466] As shown in FIG. 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general processor or a special-purpose processor, etc., such as a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control a communication apparatus (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 9100 is configured to perform any of the above methods. Optionally, the one or more processors 9101 are configured to invoke instructions to cause the communication device 9100 to perform any of the above methods.

[0467] In some embodiments, the communication device 9100 further includes one or more transceivers 9102. When the communication device 9100 includes one or more transceivers 9102, the transceiver 9102 performs at least one of the communication steps (e.g., steps S2101 and / or steps S2103 and / or steps S2104 and / or steps S2106, etc., but not limited to) in the above methods, and the processor 9101 performs at least one of the other steps (e.g., steps S2102 and / or steps S2105 and / or steps S2107, etc., but not limited to). In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc., can be replaced by each other, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be replaced by each other.

[0468] In some embodiments, the communication device 9100 further includes one or more memories 9103 for storing data. Optionally, all or part of the memory 9103 can also be outside the communication device 9100. In optional embodiments, the communication device 9100 can include one or more interface circuits 9104. Optionally, the interface circuit 9104 is connected to the memory 9103, and the interface circuit 9104 can be configured to receive data from the memory 9103 or other devices, and can be configured to send data to the memory 9103 or other devices. For example, the interface circuit 9104 can read data stored in the memory 9103 and send the data to the processor 9101.

[0469] The communication device 9100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0470] FIG. 9B is a structural schematic diagram of a chip 9200 according to an embodiment of the present disclosure. For the case where the communication device 9100 is a chip or a chip system, the structural schematic diagram of the chip 9200 shown in FIG. 9B can be referred to, but is not limited thereto.

[0471] The chip 9200 includes one or more processors 9201. The chip 9200 is configured to perform any of the above methods.

[0472] In some embodiments, the chip 9200 further includes one or more interface circuits 9202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 9200 further includes one or more memories 9203 for storing data. Optionally, all or part of the memory 9203 can be outside the chip 9200. Optionally, the interface circuit 9202 is connected to the memory 9203, and the interface circuit 9202 can be configured to receive data from the memory 9203 or other devices, and the interface circuit 9202 can be configured to send data to the memory 9203 or other devices. For example, the interface circuit 9202 can read data stored in the memory 9203 and send the data to the processor 9201.

[0473] In some embodiments, the interface circuit 9202 performs at least one of the communication steps (such as steps S2101 and / or steps S2103, but not limited thereto) in the above methods. The interface circuit 9202 performing the communication steps in the above methods, for example, means that the interface circuit 9202 performs data interaction between the processor 9201, the chip 9200, the memory 9203, or a transceiver device. In some embodiments, the processor 9201 performs at least one of the other steps (such as steps S2102 and / or steps S2104, but not limited thereto).

[0474] The modules and / or devices described in various embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated according to circumstances. Alternatively, part or all of the steps can also be performed by multiple modules and / or devices in cooperation, which is not limited here.

[0475] The disclosure further provides a storage medium having instructions stored thereon, which, when executed on the communication device 9100, causes the communication device 9100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a transitory storage medium.

[0476] The disclosure further provides a program product, which, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Alternatively, the program product is a computer program product.

[0477] The disclosure further provides a computer program, which, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. An information processing method, characterized in that: Performed by network devices, including: A first message is sent to a terminal, wherein the first message includes an algorithm identifier; the algorithm identifier is used by the terminal to determine an authenticated encryption (AE) algorithm for security-related processing.

2. The method according to claim 1, characterized in that The AE algorithm is AEAD (Authenticated Encryption with Associated Data).

3. The method according to claim 1 or 2, characterized in that The first message is further used to determine the operating mode of the AE algorithm; the operating mode is one of the following: Confidentiality protection and integrity protection; Integrity protection; Confidentiality protection.

4. The method according to claim 3, characterized in that The confidentiality protection and integrity protection include one of the following: Unified confidentiality protection and integrity protection; Separate confidentiality and integrity protection.

5. The method according to claim 3 or 4, characterized in that The first message includes a working mode indication; wherein the working mode indication is used to indicate that the working mode is: the confidentiality protection and integrity protection, or the integrity protection, or the confidentiality protection.

6. The method according to claim 3 or 4, characterized in that When the first message does not include an operating mode indication, the first message is used to indicate that the operating mode is the confidentiality protection and integrity protection; or, When the first message does not include the working mode indication but includes the algorithm identifier, the algorithm identifier is also used to indicate the working mode.

7. The method according to claim 6, characterized in that The algorithm identifier includes at least one of the following: a first algorithm identifier, a second algorithm identifier, and / or a third algorithm identifier; the first algorithm identifier, the second algorithm identifier, and the third algorithm identifier each include at least one of the following: A first algorithm indication, used to indicate that the working mode is the integrity protection; A second algorithm indication, used to indicate that the working mode is confidentiality protection; A third algorithm indication, used to indicate that the working mode is the confidentiality protection and integrity protection; a fourth algorithm indication, used to indicate that the working mode is not to perform the integrity protection; The fifth algorithm indication is used to indicate that the working mode is not to perform the confidentiality protection.

8. The method according to any one of claims 1 to 7, characterized in that The algorithm identifier includes at least one of the following: A first algorithm identifier, where the first algorithm identifier is used to indicate an AE algorithm based on Snow 5G; A second algorithm identifier, where the second algorithm identifier is used to indicate an AE algorithm based on AES-256; A third algorithm identifier is used to indicate an AE algorithm based on ZUC-256.

9. The method according to any one of claims 1 to 8, characterized in that The first message further includes at least one of the following: Random numbers; Ciphertext; A working mode indication, wherein the working mode indication is used to indicate the working mode; Non-access layer message check code NAS MAC; Access layer message check code MAC-I; A first length, where the first length is used to indicate the length of the NAS MAC; a second length, where the second length is used to indicate the length of the MAC-I; A key indicator, wherein the key indicator is used to indicate an intermediate key; A terminal capability indication is used to indicate the algorithm identifier of the AE algorithm supported by the terminal.

10. The method according to claim 9, characterized in that The network device is a first network element; the first message includes at least one of the following: the random number; the ciphertext; the algorithm identifier; the working mode indication; the NAS MAC; the first length; a key indicator; and the terminal capability information.

11. The method according to claim 9, characterized in that The network device is an access network device; the first message includes at least one of the following: the random number; the ciphertext; the algorithm identifier; the working mode indication; the MAC-I; the second length; the key indicator; and the terminal capability information.

12. The method according to claim 11, characterized in that The algorithm identifier is used to indicate an AE algorithm related to a radio resource control RRC message or an AE algorithm related to a user plane UP message; or, The working mode indication is used to indicate the working mode related to the RRC message or to indicate the working mode related to the UP message.

13. The method according to claim 8, 11 or 12, characterized in that: The method further comprises: Obtaining policy information from the second network element; wherein the policy information includes one of the following: A first policy indication is used to indicate that authenticated encryption or partial encryption must be used; The second policy indication is used to indicate that authenticated encryption or partial encryption is preferred; The third policy indication is used to indicate that authenticated encryption or partial encryption does not need to be used.

14. The method according to any one of claims 9 to 12, characterized in that The working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm includes at least one of the following: the key indicator, the algorithm identifier, the NAS MAC, the first length, the random number, and the working mode indication; or, The working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm includes at least one of the following: the key indicator, the algorithm identifier, the MAC-I, the second length, the random number and the working mode indication.

15. The method according to any one of claims 9 to 12 or 14, characterized in that: The working mode is separate confidentiality protection and integrity protection, and the first message does not include the ciphertext; or, The working mode is integrity protection, and the first message does not include the ciphertext.

16. The method according to any one of claims 9 to 12, or 14 to 15, characterized in that The first message includes the random number, and the random number is used by the terminal to determine the expected NAS MAC or the expected MAC-I.

17. An information processing method, characterized in that: Executed by the terminal, including: A first message sent by a network device is received, wherein the first message includes an algorithm identifier; the algorithm identifier is used by the terminal to determine an authenticated encryption (AE) algorithm for security-related processing.

18. The method according to claim 17, characterized in that The AE algorithm is AEAD (Authenticated Encryption with Associated Data).

19. The method according to claim 17 or 18, characterized in that The first message is further used to determine the operating mode of the AE algorithm; the operating mode is one of the following: Confidentiality protection and integrity protection; Integrity protection; Confidentiality protection.

20. The method according to claim 19, characterized in that The confidentiality protection and integrity protection include one of the following: Unified confidentiality protection and integrity protection; Separate confidentiality and integrity protection.

21. The method according to claim 19 or 20, characterized in that The first message includes a working mode indication; wherein the working mode indication is used to indicate that the working mode is: the confidentiality protection and integrity protection, or the integrity protection, or the confidentiality protection.

22. The method according to claim 19 or 20, characterized in that The method further comprises: Determining, based on the first message not including an operating mode indication, that the operating mode is the confidentiality protection and integrity protection; or, Based on the fact that the first message does not include the working mode indication but includes the algorithm identifier, the working mode is determined according to the algorithm identifier.

23. The method according to claim 22, characterized in that The algorithm identifier includes at least one of the following: a first algorithm identifier, a second algorithm identifier, and / or a third algorithm identifier; the first algorithm identifier, the second algorithm identifier, and the third algorithm identifier each include at least one of the following: A first algorithm indication, used to indicate that the working mode is the integrity protection; A second algorithm indication, used to indicate that the working mode is the confidentiality protection; A third algorithm indication, used to indicate that the working mode is the confidentiality protection and integrity protection; a fourth algorithm indication, used to indicate that the working mode is not to perform the integrity protection; The fifth algorithm indication is used to indicate that the working mode is not to perform the confidentiality protection.

24. The method according to any one of claims 17 to 23, characterized in that The algorithm identifier includes at least one of the following: A first algorithm identifier, where the first algorithm identifier is used to indicate an AE algorithm based on Snow 5G; A second algorithm identifier, where the second algorithm identifier is used to indicate an AE algorithm based on AES-256; A third algorithm identifier is used to indicate an AE algorithm based on ZUC-256.

25. The method according to any one of claims 17 to 24, characterized in that The first message includes at least one of the following: Random numbers; Ciphertext; A working mode indication, wherein the working mode indication is used to indicate the working mode; Non-access layer message check code NAS MAC; Access layer message check code MAC-I; A first length, where the first length is used to indicate the length of the NAS MAC; a second length, where the second length is used to indicate the length of the MAC-I; A key indicator, wherein the key indicator is used to indicate an intermediate key; A terminal capability indication is used to indicate the algorithm identifier of the AE algorithm supported by the terminal.

26. The method according to claim 25, characterized in that The network device is a first network element; the first message includes at least one of the following: the random number; the ciphertext; the algorithm identifier; the working mode indication; the NAS MAC; the first length; a key indicator; and the terminal capability information.

27. The method according to claim 25, characterized in that The network device is an access network device; the first message includes at least one of the following: the random number; the ciphertext; the algorithm identifier; the working mode indication; the MAC-I; the second length; the key indicator; and the terminal capability information.

28. The method according to claim 27, characterized in that The algorithm identifier is used to indicate an AE algorithm related to a radio resource control RRC message or an AE algorithm related to a user plane UP message; or, The working mode indication is used to indicate the working mode related to the RRC message or to indicate the working mode related to the UP message.

29. The method according to any one of claims 25 to 28, characterized in that The working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm includes at least one of the following: the key indicator, the algorithm identifier, the NAS MAC, the first length, the random number, and the working mode indication; or, The working mode is unified confidentiality protection and integrity protection, and the associated data of the AE algorithm includes at least the following: the key indicator, the algorithm identifier, the MAC-I, the second length, the random number and the working mode indication.

30. The method according to any one of claims 25 to 29, characterized in that The working mode is separate confidentiality protection and integrity protection, and the first message does not include the ciphertext; or, The working mode is integrity protection, and the first message does not include the ciphertext.

31. The method according to any one of claims 25 to 30, characterized in that The first message includes the random number, and the random number is used by the terminal to determine the expected NAS MAC or the expected MAC-I.

32. The method according to any one of claims 25 to 31, characterized in that The method further comprises at least one of the following: Sending a rejection message to the first network element or sending the rejection message to the access network device based on that the terminal capability indication stored in the terminal is different from the terminal capability indication in the first message; Sending a rejection message to the first network element based on the terminal determining that the length of the received NAS MAC is different from the first length; Based on the terminal determining that the length of the received MAC-I is different from the second length, a rejection message is sent to the access network device.

33. An information processing method, characterized in that: The method is executed by the second network element and includes: receiving policy information sent by a third network element; Sending the policy information to the access network device; The policy information includes one of the following: A first policy indication is used to indicate that authenticated encryption or partial encryption must be used; The second policy indication is used to indicate that authenticated encryption or partial encryption is preferred; The third policy indication is used to indicate that authenticated encryption or partial encryption does not need to be used.

34. The method according to claim 33, wherein The second network element is a session management function SMF; and / or, The third network element is the unified data management function UDM.

35. A network device, characterized in that: include: The first transceiver module is configured to send a first message to the terminal, wherein the first message includes an algorithm identifier; the algorithm identifier is used by the terminal to determine the authenticated encryption (AE) algorithm for security-related processing.

36. A terminal, characterized in that: include: The second transceiver module is configured to receive a first message sent by the network device, wherein the first message includes an algorithm identifier; the algorithm identifier is used by the terminal to determine the authentication encryption AE algorithm for related processing.

37. A second network element, characterized in that: include: a third transceiver module, configured to receive policy information sent by a third network element; The third transceiver module is configured to send policy information to the access network device; The policy information includes one of the following: A first policy indication is used to indicate that authenticated encryption or partial encryption must be used; The second policy indication is used to indicate that authenticated encryption or partial encryption is preferred; The third policy indication is used to indicate that authenticated encryption or partial encryption does not need to be used.

38. A communication device, characterized in that: include: one or more processors; The communication device is used to execute the information processing method according to any one of claims 1 to 16, or claims 17 to 32, or claims 33 to 34.

39. A communication system, characterized in that: include: A terminal, a network device, and a second network element; wherein the terminal is configured to implement the information processing method according to any one of claims 1 to 16, the network device is configured to implement the information processing method according to any one of claims 17 to 32, and the second network element is configured to implement the information processing method according to any one of claims 33 to 34.

40. A storage medium storing instructions, characterized in that: When the instruction is executed on a communication device, the communication device is caused to execute the information processing method according to any one of claims 1 to 16, or claims 17 to 32, or claims 33 to 34.

41. A computer program product, comprising a computer program or instructions, characterized in that: When the computer program or instruction is executed by a processor, the information processing method according to any one of claims 1 to 16, or claims 17 to 32, or claims 33 to 34 is implemented.

Citation Information

Patent Citations

  • Data processing method and device

    CN110830993A

  • Method and system of authenticated encryption and decryption

    CN112910650A

  • Communication method and device

    CN115884170A

  • Method and device for authenticating UE in wireless communication system

    WO2023058826A1