Communication method and related apparatus
By using an independent session key and authentication key system, combined with third-party identity authentication, the risk of session key leakage is resolved, communication security is improved, and the privacy and integrity of information transmission are ensured.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2026-04-02
AI Technical Summary
In enterprise networks, there is a risk of leakage when session keys are derived from base keys, which can lead to the theft of communication data. Existing technologies cannot guarantee the communication security of terminals and access points.
An independent session key and authentication key system is adopted. The identity of the second node is authenticated by the third node, and the authentication key is used to verify the information, ensuring the security of information transmission and forward security.
It improves the communication security between terminals and access points, ensures the privacy and integrity of information transmission, and reduces the risk of session key leakage.
Smart Images

Figure CN2025122361_02042026_PF_FP_ABST
Abstract
Description
Communication method and related apparatus
[0001] The present application claims priority to the Chinese patent application No. 202411400384.6, filed on September 30, 2024, and entitled "A communication method and related apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, in particular to a communication method and related apparatus. BACKGROUND
[0003] In the era of rapid development of mobile Internet, communication security has gradually become a key issue in the field of communication. Especially for wireless transmission, nodes and access points (APs) need to perceive each other in a complex space first, and then perform an access process to realize data transmission between them.
[0004] In the process of terminal accessing an AP, identity authentication is needed between the two to ensure the identity of the other party is trusted. Especially for enterprise networks, considering internal network security, enterprise networks need to perform security authentication on accessing users to ensure that the identity of the terminal entering the network is trusted. In an enterprise network, a terminal that has passed security authentication is issued a base key, and the terminal and the AP can derive a session key between them based on the base key to realize secure communication between the terminal and the AP. Such an access process can realize "only legitimate users can access the network". However, the session key is derived from the base key, and when the base key is cracked, there is a huge risk of leakage of the session key. Currently, there have been cases of communication data between terminals and APs being stolen due to the base key being broken.
[0005] Therefore, how to improve the communication security performance of terminals and APs is a hot issue being studied by those skilled in the art. SUMMARY
[0006] The present application provides a communication method and related apparatus, which can separate the session key and the authentication key, and ensure the high privacy of the session key of the node while realizing the identity authentication of the node, thereby improving the communication security performance of the node.
[0007] In a first aspect, the present application provides a communication method, comprising: obtaining a first key from a second node through security context negotiation, the first key being used for security protection of a session between the first node and the second node; and receiving a second key from a third node, the second key being used for verifying information transmitted between the first node and the second node, wherein the second node is a node requesting association with the first node, i.e., the method is applied in a scenario where the second node requests association with the first node; and the third node is used for authenticating the second node, e.g., the third node can directly or indirectly interact with the second node to authenticate the identity of the second node.
[0008] Optionally, the second key is sent in a case where the third node successfully performs an authentication process.
[0009] The communication method can be applied to a node, which is a device with communication capability. For the sake of convenience, the first node is taken as an example to be described herein. In a specific implementation process, the method can be executed by a software module, a hardware module or a combination of software and hardware in the first node, e.g., a chip or a processor in the node.
[0010] In the present application, in a scenario where the second node is associated with the first node, two sets of key systems are established in the first node, one of which is a session key system, and the other of which is an authentication key system. The session key is obtained through security context negotiation with the second node and does not pass through other devices. The authentication key is distributed by the third node.
[0011] The session key is a key used for security protection of a session transmitted between nodes, and the security protection includes one or more of encryption, integrity protection and authentication encryption. The second key is determined by the third node after performing an authentication process, and can be regarded as an authentication key. The second node can also determine a key associated with the second key determined by the third node in the authentication process. Therefore, the information transmitted between the first node and the second node can be verified based on the second key. Understandably, since the first node has transmitted some information to the second node before receiving the second key, e.g., information transmitted in a security context negotiation process, the security of the information can not have been checked (even if it has been checked, the check is performed under the condition that the identity of the second node has not been authenticated). Since the second key is a key distributed by the third node and is closely related to the identity of the second node, the second key is used to verify the information transmitted between the first node and the second node, which can ensure that the information transmitted between the first node and the second node is secure and has not been tampered with, and is conducive to ensuring the forward security of the information.
[0012] In summary, the session key and the authentication key are independent of each other in the present application, which ensures high privacy of the session key between the first node and the second node, and improves the communication security performance of the node. Further, the identity of the node is authenticated by using the third node, and the information is checked with the second node based on the authentication key distributed by the third node, which can further improve the communication security performance of the first node.
[0013] In some possible implementation, the second key is not used for security protection of the information transmitted by the first node and the second node. In this way, the functions of the first key and the second key can be independent of each other.
[0014] In some possible implementation, the security protection and the information checking of the present application occur in different stages. Among them, the security protection is performed synchronously with the transmission of the information, such as encryption of the information, security protection is usually completed at the same time as the transmission of the information, for example, the information is encrypted when the message is transmitted, and for another example, the check code used for checking the integrity of the information is usually carried in the same message or related messages (considering the case of message segmentation) as the protected information. The information checking is usually performed after the transmission of the information, such as triggering the information checking of the message or the content of the message at a certain time after the message is received. Therefore, the information checked by the second key is the information transmitted before (for example, before receiving the second key, or before saving the second key). Exemplarily, the second key is used to check the information transmitted by the first node and the second node in the security context negotiation process.
[0015] In a possible implementation of the first aspect, the method further includes: interacting with the third node an authentication message, the authentication message being used for authenticating the second node. Among them, the interaction message includes a received message and / or a sent message. For example, the first node can send an authentication message M1 to the third node, the message M1 including the information of the second node (for example, indicating an account number, or a password, etc.), and the third node can authenticate whether the identity of the second node is trusted based on the information of the second node. Alternatively, the first node can receive an authentication message M2 sent by the third node, and the message M2 includes authentication data of the second node (for example, data indicating whether the identity of the second node is trusted, or a password, etc.).
[0016] In another possible implementation of the first aspect, the method further includes: interacting with the second node an authentication message, the authentication message being used for authenticating the second node. For example, the first node can send a message M3 to the second node, and the message M3 includes the information of the third node or the authentication data of the second node sent by the third node. For another example, the first node can receive a message M4 sent by the second node, and the message M4 includes the authentication data of the second node (for example, information indicating whether the authentication process is completed and / or data indicating whether the identity of the second node is trusted, etc.).
[0017] In a further possible implementation form of the first aspect, the method further comprises: interacting with the third node and the second node an authentication message. At this time, the first node interacts with the first node an authentication message and interacts with the second node an authentication message. The authentication message interacted with the third node and the authentication message interacted with the second node can be different, of course, can also be the same. Further, the interaction process can be different, or the same.
[0018] In a further possible implementation form of the first aspect, before obtaining the first key through the security context negotiation with the second node, the method further comprises: broadcasting an authentication manner indication, the authentication manner indication being used to indicate the first authentication manner, the first authentication message being related to the first authentication manner.
[0019] The authentication manner is a manner of authenticating the identity of the second node requesting access. In the above implementation form, the first node can broadcast the authentication manner indication to indicate one or more authentication manners (i.e. the first authentication manner), and then the first node interacts with the second node an authentication message according to the first authentication manner. By broadcasting the authentication manner indication, the second node can evaluate whether it supports the corresponding authentication manner based on the authentication manner indication, so as to avoid the probability of association failure due to authentication capability mismatch after initiating the association process, and to avoid waste of computing resources and network resources.
[0020] In some scenarios, the first node is an accessed node, which can be referred to as a management node (or an access point), and the second node is a node requesting association, which can be referred to as a terminal node. The management node can send a broadcast message, and the terminal node can receive the broadcast message to perceive the management node. The authentication manner indication can be carried in the broadcast message of the management node. Exemplarily, taking a star flash communication system as an example, the management node is also referred to as a G node, and the terminal node is also referred to as a T node. The broadcast message can be referred to as a communication domain system message. It should be understood that the naming of nodes, messages, information (such as keys, parameters, etc.) in the present disclosure is only an example, and the name can be replaced in the specific implementation process.
[0021] In a further possible implementation form of the first aspect, the first node can select the first authentication manner from authentication manners supported by both the second node and the first node, and indicate the selected first authentication manner to the second node.
[0022] As a possible implementation, the method further comprises: receiving an authentication capability indication from the second node, and sending the authentication manner indication to the second node. The authentication capability indication is used to indicate authentication manners supported by the second node, the authentication manner indication is used to indicate the first authentication manner, the first authentication manner belongs to an authentication manner with the highest priority among authentication manners supported by the first node and the second node, and the authentication message is related to the first authentication manner. Optionally, the priority here is determined by a priority policy predefined or pre-designed by the first node.
[0023] In the above embodiment, the first node can select the authentication mode according to the authentication capability of the second node, so that the first node can adapt to nodes with different authentication capabilities, and improve the compatibility of the network.
[0024] Optionally, the authentication capability indication can be carried in the first message, and the authentication mode indication can be carried in the second message or the fourth message. Alternatively, the authentication capability indication can be carried in the third message, and the authentication mode indication can be carried in the fourth message. The first message and the third message are described below.
[0025] In a further possible implementation form of the first aspect, the authentication mode indication is configured to indicate one of the following authentication modes: personal, enterprise-extensible authentication protocol (EAP) authentication, enterprise-certificate authentication, or enterprise-customized authentication, etc. That is, the first authentication mode can be at least one of the above authentication modes.
[0026] In some schemes, the first node can support both personal and enterprise authentication modes, so that the communication capability of the first node can adapt to personal use scenarios and enterprise use scenarios, and improve the usability of the first node.
[0027] In a further possible implementation form of the first aspect, the authentication mode using the third node to authenticate the identity of the second node is used in the enterprise version. That is, the authentication mode indication is configured to indicate one of the following authentication modes: enterprise-extensible authentication protocol (EAP) authentication, enterprise-certificate authentication, or enterprise-customized authentication, etc.
[0028] Further, in the personal version, the first node authenticates the identity of the second node by receiving a second authentication parameter from the second node. The second authentication parameter can be carried in the third message, and the third message is described below.
[0029] In a further possible implementation form of the first aspect, the obtaining the first key from the second node in the security context negotiation comprises: receiving a first message from the second node, the first message comprising a first key negotiation parameter, the first key being related to the first key negotiation parameter; and sending a second message to the second node, the second message comprising a second key negotiation parameter, the first key being related to the second key negotiation parameter. In the above implementation form, the first node and the second node can exchange the key negotiation parameters to determine the first key locally. Since the key negotiation parameters are only exchanged between the first node and the second node, the privacy of the first key is higher, and thus the communication security between the first node and the second node is higher.
[0030] For example, the first message is an association request message, which is used to request association of the first node, e.g., comprising information of the second node, such as an identity (ID), capability information, etc. The second message is a security context request message, which is used for the second node to determine a security context, the security context comprising one or more of a shared key, a master key and a security parameter, etc.
[0031] In a further possible implementation form of the first aspect, the method further comprises: receiving a third message from the second node, the third message being used to respond to the second message; and sending a fourth message to the second node, the fourth message being used to indicate whether the association between the first node and the second node is established.
[0032] Optionally, the third message and the fourth message can also be regarded as messages in the security context negotiation process. For example, the third message is a security context response message, and the fourth message is an association establishment message.
[0033] Optionally, the third message is secured based on a session key, comprising encryption and / or integrity protection. Further, the fourth message is secured based on the session key, comprising encryption and / or integrity protection.
[0034] In a further possible implementation form of the first aspect, the second message further comprises a first authentication parameter field, the first authentication parameter field being used to carry a first authentication parameter, and a value of the first authentication parameter field being a default value or a random value.
[0035] In some solutions, the first authentication parameter is used to authenticate the identity of the first node. In the above implementation form, the authentication process between the first node and the second node can be omitted, and thus the carrying of the authentication parameter field originally defined in the second message can be set to a default value or a random value. In this way, the multiplexing degree of signaling can be improved, a new signaling format does not need to be redefined, and the complexity of the signaling interaction process is reduced.
[0036] Alternatively, in some schemes, the second message does not include the first authentication parameter field.
[0037] In a further possible implementation form of the first aspect, the third message includes a second authentication parameter field, the second authentication parameter field is configured to carry the second authentication parameter, the first node does not perform a check procedure related to a value of the second authentication parameter field, and / or the value of the second authentication parameter field is a default value or a random value.
[0038] In the above implementation form, even if the second node calculates the second authentication parameter, the first node can skip the procedure related to the second authentication parameter.
[0039] Alternatively, in some schemes, the third message does not include the second authentication parameter field.
[0040] In a further possible implementation form of the first aspect, the method further comprises receiving a first check parameter from the second node, and verifying the first check parameter. The first check parameter is related to the second key, the key agreement algorithm capability of the first node, the authentication mode indication, the second message, the fourth message and the first freshness parameter included in the first message. Accordingly, the first node can generate the first check code based on the same manner to verify whether the first check parameter is correct. Illustratively, verifying the first check parameter comprises verifying the first check parameter based on the second key, the key agreement algorithm capability of the first node, the authentication mode indication, the first freshness parameter, the second message and the fourth message.
[0041] In the above implementation form, the second node can calculate the first check parameter based on the authentication key obtained by the second key determined by the second node (i.e. the second key local to the second node), and send the first check parameter to the first node. Accordingly, the first node can check the first check parameter based on the same information to verify whether the information to be checked in the first node is consistent with the information to be checked in the second node, so as to check that the obtained information between the first node and the second node is secure and not tampered, which is beneficial to guarantee the forward security of the information.
[0042] In a possible implementation form, the first check parameter is carried in a fifth message. Further, the fifth message is secured by a session key. In some schemes, the fifth message is referred to as a session key confirmation response.
[0043] In a further possible implementation form of the first aspect, after verifying the first check parameter, the method further comprises opening the first communication port to allow the second node to access the resource in the case that the verification of the first check parameter is successful. In this way, it can be determined that the identity of the second node is trusted and the information interacted is not tampered, which can improve the security of the network.
[0044] In a further possible implementation form of the first aspect, the method further comprises: generating a second check parameter based on the second key, a second fresh parameter, the first message and a third message, and sending the second check parameter to the second node. The second fresh parameter is included in the second message, and the second check parameter is used to check the second fresh parameter, the first message and the third message.
[0045] In the above solution, the first node can generate the second check parameter based on the second key and information transmitted between the first node and the second node, and the second check parameter can be used to check the correctness of the information at the second node side, which helps to ensure the forward security of the information at the second node side.
[0046] Optionally, the second check parameter is carried in a sixth message. Further, the sixth message is secured by a session key. In some solutions, the sixth message is referred to as a session key request.
[0047] In a further possible implementation form of the first aspect, after obtaining the first key, the security protection of the signaling plane between the first node and the second node is in an activated state. The activation of the security protection of the signaling plane can enable the subsequent signaling messages transmitted between the first node and the second node, such as the second message, the third message, the fourth message, the fifth message and the sixth message, to be secured, further improving the security of the nodes.
[0048] In a second aspect, the present application provides a communication method, comprising: performing security context negotiation with a first node to obtain a first key, the first key being used to secure a session between the first node and a second node; and interacting with an authentication message with a third node or the first node, the first node being connected to the third node, the authentication message being related to an authentication protocol, and the third node being used to authenticate the second node; generating a second key based on the authentication protocol, the second key being used to check information transmitted between the first node and the second node. The first node is a node associated with the second node.
[0049] In the present application, the second node negotiates with the first node to obtain a session key between the two nodes, which is used to secure the session between the two nodes. The identity authentication of the second node is implemented by interacting with an authentication message between the third node and the first node, and the interaction process of the authentication message is related to an authentication protocol. The second node can determine a second key based on the authentication protocol, and the second key can be regarded as an authentication key, which can indicate that the identity of the second node is trusted. The first node can also obtain the second key associated with the second node from the third node.
[0050] Since the second key is determined after the second node has transmitted some information with the first node, such as the information transmitted in the security context negotiation procedure, the security of the information can not have been checked (even if it has been checked, the check is performed before the identity of the second node is authenticated), and since the second key is closely related to the trustworthiness of the identity of the second node, using the second key to verify the information transmitted between the first node and the second node can ensure that the information transmitted between the first node and the second node is secure and has not been tampered with, and is conducive to ensuring the forward security of the information.
[0051] In summary, the present application separates the session key and the authentication key from each other, and ensures high privacy of the session key of the first node and the second node. Further, using the third node to authenticate the identity of the second node and using the authentication key to verify the information transmitted between the first node and the second node can further improve the communication security of the nodes.
[0052] In some possible implementations, the second key is not used to securely protect the information transmitted between the first node and the second node.
[0053] In some possible implementations, the secure protection and the information verification occur in different stages. The information verified by the second key can be information transmitted by the first node before the second key is received. Exemplarily, the second key is used to verify the information transmitted between the first node and the second node in the security context negotiation procedure.
[0054] In another possible implementation of the second aspect, before the security context negotiation with the first node and obtaining the first key, the method further includes: receiving a broadcast message from the first node, the broadcast message including an authentication mode indication, the authentication mode indication being used to indicate the first authentication mode, and the authentication message being related to the first authentication mode.
[0055] In another possible implementation of the second aspect, before the interaction of the authentication message with the third node or the first node, the method further includes: sending an authentication capability indication to the first node, the authentication capability indication being used to indicate the authentication modes supported by the second node, receiving an authentication mode indication from the first node, the authentication mode indication being used to indicate the first authentication mode, the first authentication mode being the highest-priority authentication mode among the authentication modes supported by the first node and the second node, and the authentication message being related to the first authentication mode. Optionally, the priority is determined according to a priority policy predefined or pre-designed for the G node.
[0056] Optionally, the authentication capability indication can be carried in the first message, and the authentication mode indication can be carried in the second message or the fourth message. Alternatively, the authentication capability indication can be carried in the third message, and the authentication mode indication can be carried in the fourth message.
[0057] In a further possible implementation form of the second aspect, the authentication mode indication is configured to indicate one of the following authentication modes: personal, enterprise-EAP authentication, enterprise-certificate authentication, or enterprise-custom authentication.
[0058] In a further possible implementation form of the second aspect, the authentication mode indication is configured to indicate one of the following authentication modes: enterprise-EAP authentication, enterprise-certificate authentication, or enterprise-custom authentication.
[0059] In a further possible implementation form of the second aspect, the security context negotiation with the second node to obtain the first key comprises: sending a first message to the first node, the association request message comprising first key negotiation parameters, the first key being related to the first key negotiation parameters, and receiving a second message from the first node, the second message comprising second key negotiation parameters, the first key being related to the second key negotiation parameters.
[0060] In a further possible implementation form of the second aspect, the method further comprises: sending a third message to the first node, the third message being configured to respond to the second message, and receiving a fourth message from the first node, the fourth message being configured to indicate whether the association between the first node and the second node is established.
[0061] Optionally, the third message and the fourth message can also be regarded as messages in the security context negotiation procedure.
[0062] Optionally, the third message is secured based on a session key. Further, the fourth message is secured based on the session key.
[0063] In a further possible implementation form of the second aspect, the second message further comprises a first authentication parameter field configured to carry a first authentication parameter, the second node not performing a check procedure related to a value of the first authentication parameter field, and / or the value of the first authentication parameter field being a default value or a random value.
[0064] Alternatively, in some schemes, the second message does not comprise the first authentication parameter field.
[0065] In a further possible implementation form of the second aspect, the third message comprises a second authentication parameter field configured to carry a second authentication parameter, the value of the second authentication parameter field being a default value or a random value.
[0066] Alternatively, in some schemes, the third message does not comprise the second authentication parameter field.
[0067] In a further possible implementation form of the second aspect, the method further comprises receiving a second verification parameter from the first node, and verifying the second verification parameter. The second verification parameter is related to the second freshness parameter, the first message and the third message, and the second freshness parameter is comprised in the second message. Verifying the second verification parameter comprises verifying the second verification parameter based on the second key, the second freshness parameter, the first message, the third message and the second verification parameter.
[0068] Optionally, the second verification parameter is carried in a sixth message. Further, the sixth message is secured by the session key. In some solutions, the sixth message is referred to as a session key request.
[0069] In a further possible implementation form of the second aspect, after obtaining the first key, the signaling plane security between the first node and the second node is in an activated state.
[0070] In a further possible implementation form of the second aspect, the method further comprises generating a first verification parameter based on the second key, a key agreement algorithm capability of the first node, the authentication mode indication, the first freshness parameter, the second message and the fourth message, and sending the first verification parameter to the first node.
[0071] In a possible implementation form of the second aspect, the first verification parameter is carried in a fifth message. Further, the fifth message is secured by the session key. In some solutions, the fifth message is referred to as a session key confirmation response.
[0072] In a further possible implementation form of the second aspect, the step of sending the first verification parameter to the first node is performed in case that the information verification is successful.
[0073] In a third aspect, the present application provides a communication apparatus, which comprises units or modules for performing the method described in the first aspect or any possible implementation form of the first aspect, and / or units or modules for performing the method described in the second aspect or any possible implementation form of the second aspect.
[0074] Exemplarily, the communication apparatus comprises a processing unit and a communication unit. The processing unit is configured to implement one or more of processing, determining, generating, calculating, encrypting, decrypting, etc. The communication unit is configured to implement one or more of sending, receiving, etc.
[0075] In a fourth aspect, the present application provides a node, which comprises a processor and a memory. The memory is configured to store computer instructions, and the processor is configured to invoke the computer instructions stored in the memory to implement the method described in the first aspect or any possible implementation form of the first aspect, or to implement the method described in the second aspect or any possible implementation form of the second aspect.
[0076] In a fifth aspect, the present application provides a chip, which comprises a processor and an interface circuit, the interface circuit is used for receiving signals from other communication devices (including nodes) and transmitting the signals to the processor or sending signals from the processor to other communication devices, and the processor is used for implementing the method described in the first aspect or any possible implementation manner of the first aspect, or for implementing the method described in the second aspect or any possible implementation manner of the second aspect, by means of logic circuit or executing code instructions.
[0077] In a sixth aspect, the present application provides a communication system, which comprises a first node and a second node, the first node is used for implementing the method described in the first aspect or any possible implementation manner of the first aspect, and the second node is used for implementing the method described in the second aspect or any possible implementation manner of the second aspect.
[0078] In a seventh aspect, the present application provides a terminal, which comprises the communication device described in the third aspect, or comprises the node described in the fourth aspect, or comprises the chip described in the fifth aspect, or comprises the communication system described in the sixth aspect. Optionally, the terminal can be a handheld terminal, a wearable device, a vehicle, a robot, a drone, or the like intelligent device or carrier.
[0079] In an eighth aspect, the present application provides a readable storage medium, which is used for storing a computer program, when the computer program is executed by a processor, the communication device comprising the processor implements the method described in the first aspect or any possible implementation manner of the first aspect, or implements the method described in the second aspect or any possible implementation manner of the second aspect.
[0080] In a ninth aspect, the present application provides a computer program product, when the computer program product is executed by a processor, the communication device comprising the processor implements the method described in the first aspect or any possible implementation manner of the first aspect, or implements the method described in the second aspect or any possible implementation manner of the second aspect.
[0081] The beneficial effects of the second aspect to the ninth aspect of the present application can be referred to the beneficial effects of the solution of the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0082] The drawings used in the description of the embodiments will be briefly introduced as follows.
[0083] Fig. 1 is a schematic diagram of the architecture of a communication system;
[0084] Fig. 2 is a schematic diagram of the connection relationship of nodes in a wireless BMS scenario;
[0085] FIG. 3 is a schematic diagram of connection relationship of nodes in a smart home scenario;
[0086] FIG. 4 is a schematic diagram of architecture of another communication system;
[0087] FIG. 5 is a schematic diagram of a communication method provided by an embodiment of the present application;
[0088] FIG. 6 is a schematic diagram of a security context negotiation provided by an embodiment of the present application;
[0089] FIG. 7 is a schematic diagram of a key hierarchy provided by an embodiment of the present application;
[0090] FIG. 8 to FIG. 11 are schematic diagrams of four kinds of authentication message interactions provided by embodiments of the present application;
[0091] FIG. 12 is a schematic diagram of information verification provided by an embodiment of the present application;
[0092] FIG. 13 is a schematic diagram of another information verification provided by an embodiment of the present application;
[0093] FIG. 14 is a schematic diagram of another communication method provided by an embodiment of the present application;
[0094] FIG. 15 is a schematic diagram of another communication method provided by an embodiment of the present application;
[0095] FIG. 16 is a schematic diagram of structure of a communication apparatus provided by an embodiment of the present application;
[0096] FIG. 17 is a schematic diagram of structure of a node provided by an embodiment of the present application. DETAILED DESCRIPTION
[0097] Hereinafter, some technical terms are introduced.
[0098] 1. Node
[0099] A node is a device with communication capability, including but not limited to one or more of a user device, a network device, an industrial device, etc. Among them, the user device includes one or more of a handheld terminal, a wearable terminal, a vehicle, a vehicle-mounted device, a sensing device, a smart home device, or a leisure and entertainment device, etc., the handheld terminal includes but is not limited to a mobile phone, a tablet, or a notebook computer, etc., the wearable device includes but is not limited to a headset, a smart bracelet, a smart watch, or smart glasses, etc., the vehicle includes but is not limited to a vehicle, a ship, an aircraft, rail transit (such as a subway, a high-speed rail, etc.), or a logistics robot (such as an automated guided vehicle (AGV)), etc., the vehicle-mounted device includes but is not limited to a domain controller (DC), a screen, a microphone, a sound, an electronic key, a keyless entry, a start system controller, a battery management system (BMS), a battery pack, or a battery cell, etc., the sensing device includes but is not limited to a camera, a radar, a laser radar, an illumination sensor, a temperature sensor, or a humidity sensor, etc., the smart home device includes but is not limited to a projector, a smart TV, a smart refrigerator, a smart home gateway, or a security device, etc. The leisure and entertainment device includes but is not limited to a virtual reality (VR) device, a mixed reality (MR) device, a massage chair, a home theater, a game control device, or a 4D cinema cabin, etc. The network device includes but is not limited to a router, a switch, or a base station, etc. The industrial device includes but is not limited to an industrial robot, or a mechanical arm, etc.
[0100] The present application is applicable to various networks, and the node can represent devices in various networks. For example, the present application can be applicable to a network formed by a wired communication network, a wireless communication network, or a combination of wired communication and wireless communication. For example, the wireless communication network includes a network connected by communication technologies such as SparkLink (or NearLink), 802.11b / g, Bluetooth, Zigbee, radio frequency identification (RFID), ultra-wideband (UWB) technology, or a wireless short-range communication system. And / or, the wireless communication network includes long-distance connection technologies such as long term evolution (LTE) based communication technologies, 5th generation mobile networks or 5th generation wireless systems (5th-Generation, 5G or 5G technology), global system for mobile communications (GSM), general packet radio service (GPRS), universal mobile telecommunications system (UMTS), open radio access network (ORAN), and other wireless communication technologies. For another example, the wired communication network includes a network connected by one or more of the following communication technologies: fiber-optic connection technology, vehicle-mounted wired communication technology, controller area network (CAN), local interconnect network bus (LIN), CAN flexible data rate (CAN FD), or vehicle-mounted Ethernet.
[0101] The node in the embodiments of the present application can be applied to various scenarios such as intelligent vehicles, smart homes, intelligent terminals, intelligent manufacturing, intelligent showrooms, mobile internet (MI), industrial control, self-driving, transportation safety, or internet of things (IoT).
[0102] It should be understood that in certain application scenarios or certain network types, similar communication-capable devices can not be referred to as nodes, but for the convenience of description, the communication-capable devices are collectively referred to as nodes in the embodiments of the present application.
[0103] 2. Session key
[0104] A session key is a key used for security protection of information transmitted at both ends of communication. The security protection includes one or more of confidentiality protection, integrity protection, authentication encryption, and the like, wherein the confidentiality protection needs to use an encryption key or an authentication encryption key. The integrity protection needs to use an integrity protection key or an authentication encryption key.
[0105] Encryption is used to protect the confidentiality of data, that is, to encrypt plaintext to obtain ciphertext. Correspondingly, decryption is the inverse process of encryption, that is, to decrypt ciphertext to obtain plaintext. For the convenience of description, part of the flow is described by taking the positive encryption process as an example. Encryption needs to be implemented through a corresponding encryption algorithm. The encryption algorithm can include encryption operations (such as elliptic point addition operations or exclusive or operations, etc.) and various mathematical functions with higher security. Common encryption algorithms mainly include data encryption standard (DES), triple data encryption algorithm (3DES), advanced encryption standard (AES), RSA encryption algorithm, data structure analysis algorithm (DSA), national encryption algorithm (such as SM4, etc.), Zu Chongzhi algorithm set (ZUC algorithm, such as Zu Chongzhi algorithm, encryption algorithm 128-EEA3 or integrity algorithm 128-EIA3, etc.).
[0106] Integrity protection is used to protect message integrity to determine whether a message is tampered during transmission. In addition to the integrity protection key, integrity protection also needs to be implemented through a corresponding integrity protection algorithm. For example, an integrity protection algorithm implemented through a hash algorithm is called a hash-based message authentication code (HMAC) algorithm, in which the hash algorithm can be one of MD5, SHA-1, SHA-256, and the like. Different HMAC implementations are usually marked as: HMAC-MD5, HMAC-SHA1, HMAC-SHA256, and the like. For another example, a MAC algorithm implemented based on a cipher algorithm can be called a cipher-based message authentication code (CMAC) algorithm, in which the cipher algorithm can be AES. Since there are four working modes of ECB, CBC, CFB, and OFB for AES packet encryption, integrity protection algorithms implemented based on packet encryption algorithms of different working modes can be called ECB-MAC algorithm, CBC-MAC algorithm, and the like, respectively. Further, one-key CBC-MAC (OMAC) is improved from the CBC-MAC algorithm. In addition, the integrity protection algorithm can also include Galois message authentication code mode (GMAC), Zu Chongzhi cipher algorithm (such as ZUC128, ZUC256, and the like), MD algorithm (such as MD2, MD4, or MD5, and the like).
[0107] An authenticated encryption process is used for information encryption and integrity protection. For a given information, the authenticated encryption process can generate both the ciphertext of the information and the check code of the information. Therefore, the authenticated encryption algorithm can be used as both an encryption algorithm and an integrity protection algorithm. For example, AES algorithms based on GMAC and counter encryption mode (AES-Galois / counter mode, AES-GCM) and CMAC and counter encryption mode (AES-CMAC / counter mode, AES-CCM) can perform authenticated encryption on information, can obtain the ciphertext of the information, and can generate the check code to protect the integrity of the information.
[0108] 3. Freshness parameter
[0109] The freshness parameter is applied in encryption, integrity protection, key derivation, key agreement, etc., and can also be referred to as freshness or freshness parameter. Generally, the specific value of the freshness parameter changes after each generation, so that the value of the determined freshness parameter this time is different from that of the last time, thereby improving security.
[0110] Exemplarily, the freshness parameter can include a random number (such as NONCE), a counter value, etc.
[0111] The foregoing explanations of technical terms can be optionally used in the embodiments below.
[0112] The architecture of a communication system and service scenarios to which embodiments of the present application can be applied are described below. It should be noted that the system architecture and service scenarios described herein are for the purpose of more clearly illustrating the technical solutions of the present application, and do not constitute a limitation on the technical solutions provided by the present application. It should be understood that as the system architecture evolves and new service scenarios appear, the technical solutions provided by the present application are equally applicable to similar technical problems.
[0113] The present application can be applied in a communication system. The communication system is a system for transmitting information by using electrical signals (or optical signals), which generally includes multiple nodes that communicate with each other to transmit information. The nodes in the communication system can have different identities and / or different capabilities. In an exemplary communication system, the nodes are divided into master nodes and slave nodes, the master nodes have stronger communication capabilities and have the ability to manage slave nodes, and can establish links with multiple slave nodes, so that the master nodes can communicate with each other and with the slave nodes to implement various functions.
[0114] The communication system can include wired communication systems and wireless communication systems. The wireless communication system includes short-range wireless communication systems, long-range wireless communication systems, etc. The short-range communication system is, for example, the aforementioned Bluetooth, 802.11b / g, etc. The long-range wireless communication system is, for example, LTE, 5G, etc.
[0115] The architecture of a communication system is described below taking the Bluetooth communication system as an example. As shown in FIG. 1, the communication system includes a management node and a terminal node.
[0116] The management node has communication capabilities and management capabilities, and is also referred to as a G node, an access point, or an authorized node in some scenarios. The management capabilities include communication management capabilities, such as connection management, resource scheduling, or information security management. Exemplarily, the management node can send resource management information or data scheduling information, such as access layer resource management information.
[0117] A terminal node, also referred to as a T-node in some scenarios, has communication capability and can transmit traffic with a management node. In some solutions, a terminal node is a node that receives resource management information (or data scheduling information) and transmits data according to the resource management information (or data scheduling information). Exemplarily, a terminal device can include a user equipment (UE), such as a device including a barcode, a radio frequency identification (RFID), a sensor, a global positioning system (GPS), a laser radar, a battery, and the like.
[0118] It should be understood that the identities of the management node and the terminal node are not absolute, and the identities shown herein are only exemplary naming made for the purpose of distinguishing the operations of the nodes in communication in one possible connection scenario. In some scenarios, a node belongs to two or more communication domains at the same time, and in some communication domains, the node functions as a terminal node, and in another communication domain, the node can function as a management node. For the purpose of understanding, such a node is denoted as a G(T) node in some embodiments.
[0119] In combination with FIG. 1, the terminal node and the management node can be in a connected state, and the connection relationship is represented by a dashed line. Alternatively, the management node can send a broadcast message, and the terminal node can perceive the management node based on the broadcast message. Further, the terminal node can associate with the management node, and after the terminal node and the management node complete the corresponding association process, the connection relationship can be established.
[0120] It should be noted that in FIG. 1, the connection relationship between the management node and the terminal node is represented by a dashed line, and in some solutions, the connection link includes two links, a management node direction communication link and a terminal node direction communication link. The management node direction communication link is a communication link in the direction from the management node to the terminal node, and can carry one or more of a data channel, control information, a broadcast channel, a synchronization signal, and the like from the management node to the terminal node, which can be referred to herein as a G link. The terminal node direction communication link is a communication link in the direction from the terminal node to the management node, and can carry one or more of a data channel, an access channel, or a feedback signal, and the like from the terminal node to the management node, which can be referred to herein as a T link.
[0121] Optionally, the communication between the management node and the terminal node includes unicast communication, groupcast communication, and / or broadcast communication. In some solutions, as shown in FIG. 1, the management node can connect one or more terminal nodes. In a star flash communication system, the management node supports connecting multiple terminal nodes, and the terminal node also supports associating with multiple management nodes.
[0122] The communication system applied in the present application can be applied to vehicle, smart home, smart exhibition hall, energy storage management and other scenes.
[0123] Taking the vehicle scene as an example, the communication system can be applied to a wireless battery management system (BMS) scene or a tire pressure detection scene. The wireless BMS scene can be seen from FIG. 2. The battery array management system (BAMS) is a management node, that is, a G1 node. The battery cluster management system (BCMS) is a G(T) node (dual identity node). The battery management unit (BMU) is a T node.
[0124] The smart home scene can be seen from FIG. 3. In FIG. 3, the gateway or customer premises equipment (CPE) is a G node. The sub-router, large screen, mobile phone and air conditioner are G(T) nodes. The water heater, smart curtain, sound box, microphone, printer and smart door lock are T nodes.
[0125] In some scenes (for example, in an enterprise network), in order to improve the management and control of the nodes connected to the network, a node (which can be referred to as a third node) for authentication is introduced to perform identity authentication on the nodes in the network. Please refer to FIG. 4, which is a schematic diagram of the architecture of another communication system. The communication system includes a first node 10 (which can be regarded as a management node), a second node 20 (which can be regarded as a terminal node) and a third node 30.
[0126] The first node 10 can be accessed by other nodes, and the second node 20 can request to associate with the first node 10. In the process of associating the first node 10 with the second node 20, the third node 30 can authenticate the identity of the second node 20. It should be understood that the third node 30 herein is used to refer to a functional module that can complete identity authentication. In specific embodiments, the third node 30 can be a physical device or a virtual device. Illustratively, the third node can include an authentication device, an authentication service and the like. The authentication device is, for example, a Radius server, a portal server, an access controller (AC), an authentication node or an authentication server. The authentication service is, for example, a third-party Radius or a short message server.
[0127] It should be noted that the entities of the first node 10 and the second node 20 shown in FIG. 4 are only examples.
[0128] In some scenarios, the second node 20 is issued with a base key in the case that the third node 30 authenticates the node requesting to access the network, and the first node 10 and the second node 20 can derive a session key therebetween based on the base key, so as to realize the secure communication between the first node 10 and the second node 20. However, since the base key is issued by the third node 30 and is taken as an input to derive the session key, when the base key is cracked, the session key will have a huge risk of leakage, and there are already cases of data theft due to the cracking of the base key. It can be seen that if the session key between the first node 10 and the second node 20 is cracked, the information communicated between the first node 10 and the second node 20 will be leaked, and the first node 10 and the second node 20 will face the risk of intrusion, so that the information security of the first node 10 and the second node 20 is threatened.
[0129] Therefore, the present application provides a communication method and related device, which can separate the session key and the authentication key, and ensure the high privacy of the session key of the node and improve the communication security of the node in the case of realizing the identity authentication of the node.
[0130] The method provided by the embodiments of the present application is described below.
[0131] Please refer to FIG. 5, which is a flow diagram of a communication method provided by an embodiment of the present application. Optionally, the method can be applied to a communication system, such as the communication system shown in FIG. 4. The communication method shown in FIG. 5 can include one or more steps in steps S501 to S506. It should be understood that, for the convenience of description, the steps S501 to S506 are described in this order, and it is not intended to limit the execution in the above order. The embodiments of the present application do not limit the execution order, execution time, execution times, etc. of the one or more steps. The steps S501 to S506 are as follows:
[0132] The second node performs the following step S501:
[0133] Step S501: The second node performs security context negotiation with the first node to obtain a first key.
[0134] The first node performs the following step S502:
[0135] Step S502: The first node performs security context negotiation with the second node to obtain a first key.
[0136] In step S501 and step S502, the first node and the second node have the ability of communication, which can be a standalone device or a module in a standalone device. In some communication systems, the first node is an associated node, and the second node is a node requesting to associate with the first node. In some scenarios, the first node can be referred to as a management node (or an access point, G node), and the second node can be referred to as a terminal node (or a T node). Optionally, the first node can send a broadcast message carrying information of the first node, and the second node can receive the broadcast message to perceive the first node and request to associate with the first node. In the process of requesting to associate, the first node and the second node can perform security context negotiation. The security context includes the first key, and optionally, one or more of a shared key, a master key, a security parameter (for example, a freshness parameter), or a security algorithm.
[0137] In the process of security context negotiation, the first node and the second node can interactively negotiate information, and respectively obtain the first key based on the negotiated information.
[0138] As a possible security context negotiation process, the first node and the second node exchange key negotiation parameters to respectively determine the first key. For example, referring to FIG. 6, which is a flowchart of a security context negotiation process according to an embodiment of the present application, the security context negotiation between the first node and the second node includes that the second node sends a message T1 (or a first message, and the parameter symbols shown in the present document are only examples) to the first node, and the message carries first key negotiation parameters. Correspondingly, the first node receives the message T1 from the second node, and determines the first key based on a key negotiation algorithm and the first key negotiation parameters.
[0139] Further, the first node can send a second message T2 (or a second message) to the second node, and the second message T2 carries second key negotiation parameters. Correspondingly, the second node receives the second message T2, and determines the first key based on a key negotiation algorithm and the second key negotiation parameters. In this way, the first node and the second node respectively determine the first key locally by exchanging the key negotiation parameters.
[0140] In some schemes, the message T2 can carry a first authentication parameter, which is used to verify some information, such as the content of the message T1 or some parameters carried in the message T2. In some possible schemes of the present application, the first authentication parameter is set to a default value or a random value, or the message T2 does not carry the first authentication parameter.
[0141] It should be understood that the message names and message symbols herein are only examples, and the names of messages, information, nodes, and algorithms can be replaced in the implementation process. For example, message T1 can be referred to as an association request message, which is used to request association of the first node, for example, information such as the ID, capability information, and the like of the second node. Message T2 can be referred to as a security context request message, which is used for the second node to determine the security context.
[0142] Optionally, the key agreement algorithm can include a Diffie-Hellman key exchange (DH) algorithm, an elliptic curve cryptosystem (ECC) based DH (ECDH) algorithm, a two-basis password exponential key exchange (TBPEKE) algorithm, a national secret algorithm (such as SM2, etc.), an Oakley algorithm, and the like. Among them, the TBPEKE algorithm is a secure algorithm based on elliptic curve mathematics theory, and the elliptic curve used by the TBPEKE algorithm includes one or more of the following elliptic curves: an elliptic curve defined by SM2, or Curve25519, and the like.
[0143] In some schemes, the key agreement algorithm used between the first node and the second node can be determined according to the key agreement algorithm capabilities of the first node and the second node. As a possible implementation, the first node can indicate the key agreement algorithms supported by itself to the second node, and one of the algorithms is selected by the second node as the algorithm for key agreement between the two, for example, the first node can carry the key agreement algorithm capabilities of the first node in the broadcast message, and the second node can include a key agreement algorithm indication in the message T1 sent by the second node, which is used to indicate the key agreement algorithm selected by the second node.
[0144] Optionally, the first fresh parameter can also be included in the message T1, which can also participate in determining the first key.
[0145] As a possible example, please refer to FIG. 7, which is a schematic diagram of a key hierarchy provided by the embodiments of the present application. In the key hierarchy, the shared key is a key determined by the first node and the second node through a key agreement algorithm and respective corresponding key agreement parameters. The master key is a key derived from the shared key and a first freshness parameter and a second freshness parameter, and the first freshness parameter and the second freshness parameter are respectively a freshness parameter determined by the second node and the first node. The intermediate key is a key determined from the master key and a counter (or another set of freshness parameters), and is used to derive a first key, which exemplarily includes an encryption key and an integrity protection key. In some schemes, the keys of the signaling plane and the user plane are independent, and thus the first key can include one or more of a signaling plane encryption key, a signaling plane integrity protection key, a user plane encryption key, a user plane integrity protection key, and a user plane authentication encryption key.
[0146] Further, as shown in FIG. 6, the security context negotiation procedure can further include an additional procedure after the exchange of the key agreement parameters. Exemplarily, after message T2, the second node can send a message T3 (or referred to as a third message) to the first node, and correspondingly, the first node receives the message T3 from the second node, and the message T3 is used to respond to the message T2.
[0147] In some schemes, the message T3 can carry a second authentication parameter, which is used to verify some information, such as the content of the message T2. In some possible schemes of the present application, the second authentication parameter is set to a default value or a random value, or the message T3 does not carry the second authentication parameter. Exemplarily, the message T3 is a security context response message.
[0148] Further, as shown in FIG. 6, the security context negotiation procedure can further include that the first node sends a message T4 to the second node, and correspondingly, the second node receives the message T4 (or referred to as a fourth message) from the first node. Optionally, the message T4 can be sent after the message T3, the message T2 or the message T1. In some schemes, the message T4 is used to indicate whether the association between the first node and the second node is established. Exemplarily, the message T4 has a pre-defined message format, and the message T4 is sent in the case that the association between the first node and the second node is established. Further exemplarily, the message T4 can include a temporary ID generated for the second node and / or a validity period of the master key. Further, in the case that the second node belongs to a communication group, the message T4 further includes one or more of a group key of the communication group, a group key ID, a group algorithm, a validity period of the group key, and the like. Optionally, the message T4 is an association establishment message.
[0149] Further, as shown in FIG. 6, the security context negotiation procedure can further include that the second node can send a message T5 to the first node, the message T5 being used to indicate whether the association is completed. Optionally, the message T4 is an association completion message.
[0150] In some possible implementation, the security context negotiation procedure is performed in a case that the second node requests to associate with the first node. For example, the message T1 can be used to indicate the request to associate with the first node. For another example, the association between the first node and the second node is not established before the security context negotiation procedure is performed, and the association between the first node and the second node is established after the security context negotiation procedure is performed.
[0151] In some possible implementation, before the security context negotiation procedure is performed, the first node can send a broadcast message, and accordingly, the second node can receive the broadcast message. The broadcast message can carry one or more of the following information of the first node: key negotiation capability of the first node, authentication capability of the first node, authentication mode used by the first node, and the like.
[0152] In some solutions, the identity of the second node needs to be authenticated in the process that the first node associates with the second node. In the embodiments of the present application, the identity of the second node is authenticated by a third node. There are various possible designs for the way of authenticating the identity of the second node, and in some solutions, the authentication mode can be one of the following authentication modes: personal version, enterprise version-extensible authentication protocol (EAP) authentication, enterprise version-certificate authentication, and enterprise version-self-defined authentication. The self-defined authentication can be, for example, Portal authentication. Further, each authentication mode can correspond to one or more authentication protocols. For example, the enterprise version-EAP can support one or more authentication protocols, such as one or more of the following authentication protocols: EAP-MD5, EAP-transport layer security (TLS), EAP-tunneled TLS (TTLS), EAP-light EAP (LEAP), EAP-PEAP, and the like.
[0153] In some possible solutions, if the node accessing the first node is authenticated by the third node, the authentication mode belongs to the following authentication modes: enterprise version-extensible authentication protocol (EAP) authentication, enterprise version-certificate authentication, and enterprise version-self-defined authentication.
[0154] In some possible solutions, which authentication mode is used can be determined in the following two ways:
[0155] Way 1, the first node can send an authentication mode indication to authenticate the identity mode of the second node, for the sake of description, it is referred to as the first authentication mode. For example, the first node pre-defines or pre-sets the authentication mode of the identity of the second node.
[0156] As a possible implementation, the authentication mode indication can be sent in a broadcast message. For another example, the authentication mode indication can be sent in message T2 or message T4.
[0157] Way 2, the first node and the second node negotiate to determine the first authentication mode.
[0158] As a possible implementation, the first node can select an authentication mode based on the authentication capability of the second node and indicate the selected first authentication mode to the second node. For example, the second node can send an authentication capability indication to the first node, the authentication capability indication being used to indicate the authentication modes supported by the second node. Accordingly, the first node receives the authentication capability indication from the second node and sends an authentication mode indication to the second node, the authentication mode indication being used to indicate the first authentication mode. One of the authentication modes herein belongs to the authentication modes supported by the second node. Optionally, the first authentication mode is an authentication mode supported by both the first node and the second node. Further, the first authentication mode is the highest priority authentication mode among the authentication modes supported by the first node and the second node, of course, the priority herein is determined by the priority strategy pre-defined or pre-designed by the first node.
[0159] Optionally, the authentication capability indication can be carried in message T1, and the authentication mode indication can be carried in message T2 or message T4. Or alternatively, the authentication capability indication can be carried in message T3, and the authentication mode indication can be carried in message T4. Of course, the present application is also applicable to the case of using other messages to carry the authentication capability indication and the authentication mode indication.
[0160] As another possible implementation, the second node can select an authentication mode based on the authentication capability of the first node and indicate the selected first authentication mode to the first node. Illustratively, the first node can send an authentication capability indication to the second node, the authentication capability indication being used to indicate the authentication modes supported by the first node. Accordingly, the second node receives the authentication capability indication from the first node and sends an authentication mode indication to the first node, the authentication mode indication being used to indicate the first authentication mode, which is one of the authentication modes supported by the first node. Optionally, the first authentication mode is one of the authentication modes supported by both the first node and the second node. Further, the first authentication mode is one of the authentication modes supported by the first node and the second node with the highest priority, of course, the priority being determined by a priority policy predefined or pre-designed by the second node.
[0161] The authentication modes are described above, and the authentication procedure is introduced below in combination with step S503, or further including step S504.
[0162] Step S503: The second node interacts with the third node and / or the first node with authentication messages.
[0163] In the embodiments of the present application, the identity of the second node can be authenticated by the third node, and the second node and the third node need to perform a corresponding authentication procedure. In the authentication procedure, the second node can interact with the third node and / or the first node with authentication messages (introduced below). In some schemes, the third node can authenticate the identity of the second node through the authentication messages. The related introduction of the third node can be referred to the foregoing.
[0164] In some schemes, the first node also participates in the authentication procedure, as shown in FIG. 5, the communication method provided by the present application can optionally include step S504, which is specifically as follows:
[0165] Step S504: The first node interacts with the third node and / or the second node with authentication messages.
[0166] It should be understood that based on different authentication modes and different authentication protocols, the devices interacting with the authentication messages and the specific interaction procedure of the messages and the information carried by the messages can be different. The possible implementations of four possible authentication procedures are illustratively introduced below:
[0167] In implementation 1, as shown in FIG. 8, the second node interacts with the first node authentication messages, and the first node also interacts with the third node authentication messages. Through these authentication messages, the third node can authenticate the identity of the second node. The specific interaction process of the authentication messages, the information carried in the authentication messages, and the way of authenticating the second node (i.e., the first authentication way) and / or the authentication protocol are related. Exemplarily, the message interaction process between the second node and the first node is determined based on the first authentication way, which is the way for the first node to authenticate the second node (or the way for the third node to authenticate the second node), such as one of EAP authentication, certificate authentication, and self-defined authentication.
[0168] Optionally, the second node and the third node interact with each other through authentication messages, and the first node only forwards or transmits the messages.
[0169] Alternatively, the first node can interact with the second node and the third node through authentication messages respectively, and the messages exchanged between the first node and the second node and the messages exchanged between the first node and the third node can be different.
[0170] Of course, the above two cases can be combined, such as the first node participating in the message interaction in part of the process and transmitting the messages between the second node and the third node in part of the process.
[0171] In implementation 2, as shown in FIG. 9, the second node interacts with the third node through authentication messages. Through these authentication messages, the third node can authenticate the identity of the second node. Further, the first node does not interact with the first node and the third node through authentication messages in the authentication process. The specific interaction process of the authentication messages, the information carried in the authentication messages, and the way of authenticating the second node (i.e., the first authentication way) and / or the authentication protocol are related.
[0172] In implementation 3, as shown in FIG. 10, the second node interacts with the first node and the third node through authentication messages respectively. Through these authentication messages, the third node can authenticate the identity of the second node. The specific interaction process of the authentication messages, the information carried in the authentication messages, and the way of authenticating the second node (i.e., the first authentication way) and / or the authentication protocol are related.
[0173] Optionally, the messages exchanged between the second node and the first node and the messages exchanged between the second node and the third node can be different.
[0174] In implementation 4, as shown in FIG. 11, the first node and the third node interact through authentication messages, and the second node also interacts with the third node through authentication messages. Through these authentication messages, the third node can authenticate the identity of the second node. The specific interaction process of the authentication messages, the information carried in the authentication messages, and the way of authenticating the second node (i.e., the first authentication way) and / or the authentication protocol are related.
[0175] Optionally, the messages exchanged between the first node and the third node, and the messages exchanged between the second node and the third node can be different.
[0176] Step S505: The second node generates a second key based on the authentication protocol.
[0177] The authentication protocol is related to the way of authenticating the second node, and the third node can interact with the second node based on the first authentication manner with the specified authentication protocol, and each authentication protocol can define the way of generating the key. Illustratively, the way of authenticating the second node is the EAP manner (or Enterprise-EAP manner), and the EAP manner can support authentication protocol 1 and authentication protocol 2 (only as an example). And the authentication protocol for authenticating the identity of the second node can be authentication protocol 1, and the second node can generate the second key based on authentication protocol 1, which can be regarded as an authentication key.
[0178] Optionally, the second key is also generated on the third node side based on the same authentication protocol, and the second key can be distributed to the first node.
[0179] In some possible implementation, the second key is used to verify the information transmitted between the first node and the second node. Since the second node determines the second key before some information has been transmitted between the first node and the second node, such as the information transmitted in the security context negotiation process, the security of these information can not have been checked (even if it has been checked, it is in the case that the identity of the second node has not been authenticated), since the second key is closely related to the credibility of the identity of the second node, using the second key to verify the information transmitted between the first node and the second node can ensure that the information transmitted between the first node and the second node is secure and tamper-proof, which is beneficial to ensure the forward security of the information. The specific process of information verification can be referred to the description below.
[0180] Further, the second key is not used to protect the security of the information transmitted between the first node and the second node. It should be understood that security protection and information verification occur in different stages. Among them, security protection is usually performed synchronously with the transmission of information, such as encryption and security protection of information, which are usually completed at the same time as the transmission of information. While information verification is usually performed after the transmission of information. For example, the information verified by the second key can be the information transmitted by the first node before receiving the second key. Illustratively, the second key is used to verify the information transmitted between the first node and the second node in the security context negotiation process.
[0181] As a possible example, in combination with FIG. 6, on the second node side, the information checking specifically checks one or more of the following information (i.e., the first to-be-checked information can be): the second key, part or all of the content in the broadcast message, part or all of the content in the message T1, part or all of the content in the message T2, part or all of the content in the message T3, part or all of the content in the message T4, part or all of the content in the message T5, the authentication capability indication of the first node, the authentication capability indication of the second node, the key negotiation algorithm capability of the first node, the key negotiation algorithm capability of the second node, the authentication mode indication, etc. Of course, part of the above information can overlap, for example, the authentication mode indication can be carried in the broadcast message, and for another example, the authentication capability indication of the second node can be carried in the message T1.
[0182] As a possible checking manner, please refer to FIG. 12, the information checking process of the second node is as follows:
[0183] Step S11, the first node obtains a second checking parameter based on the first to-be-checked information.
[0184] The first to-be-checked information includes the second key and the information transmitted by the first node and the second node. Exemplarily, the first to-be-checked information includes one or more of the following information: the second key, the second freshness parameter, the content of the message T1 or the content of the message T2, etc. It can be understood that the first to-be-checked information used by the first node is the information obtained on the first node side.
[0185] Further, the generation of the second checking parameter also needs to use a key derivation function (KDF). The KDF can be replaced by a hash algorithm. Exemplarily, the second checking parameter can be represented as HASHg, and the calculation method of HASHg is as follows:
[0186] HASHg = KDF (rk, NONCEg, message T1 content, message T3 content), wherein KDF is used to indicate the KDF algorithm used, and the inputs of KDF include rk, NONCEg, message T1 content and message T3 content, and their meanings are as follows: rk is the second key, and NONCEg is the second freshness parameter. It should be understood that the order between the multiple inputs of KDF here and the number of parameters are only examples, and in the specific implementation process, the number of information items included in the first to-be-checked information can be more or less, and the order of its input can also have other designs.
[0187] Step S12, the first node sends the second checking parameter to the second node.
[0188] Correspondingly, the second node receives a second check parameter. Optionally, the second check parameter can be carried in a message T6. Exemplarily, the message T6 can be referred to as a session key confirmation request.
[0189] At step S13, the second node verifies the second check parameter.
[0190] That is, the second node performs information verification based on the second check parameter and the first to-be-verified information. For example, the second node generates a first check code based on the first to-be-verified information (including the second key and the information transmitted by the first node and the second node) obtained by itself, and compares the first check code with the second check parameter to determine whether the value of the first to-be-verified information at the first node side is the same as the value of the first to-be-verified information at the second node side, so as to verify whether the first to-be-verified information is tampered with.
[0191] At step S506, the first node receives a second key from the third node.
[0192] The second key is a key distributed by the third node, which can be regarded as an authentication key for example, and the second key is used to verify the information transmitted by the first node and the second node. Further, the second key is not used to securely protect the information transmitted by the first node and the second node.
[0193] As a possible example, in combination with FIG. 6, at the first node side, the information verification is specifically to verify one or more of the following information (i.e., the second to-be-verified information can be): the second key, part or all of the content in the broadcast message, part or all of the content in the message T1, part or all of the content in the message T2, part or all of the content in the message T3, part or all of the content in the message T4, part or all of the content in the message T5, the authentication capability indication of the first node, the authentication capability indication of the second node, the key negotiation algorithm capability of the first node, the key negotiation algorithm capability of the second node, the authentication mode indication, etc. Of course, part of the above information can overlap, for example, the authentication mode indication can be carried in the broadcast message, and for another example, the authentication capability indication of the second node can be carried in the message T1.
[0194] As a possible verification manner, please refer to FIG. 13, the information verification process of the first node is as follows:
[0195] At step S21, the second node obtains a first check parameter based on the second to-be-verified information.
[0196] The second to-be-verified information includes the second key and information transmitted by the first node and the second node. For example, the second to-be-verified information includes one or more of the following: the second key, the key agreement algorithm capability of the first node, the authentication mode indication, the first freshness parameter, the content of the message T2, or the content of the message T4, and the like. It can be understood that the second to-be-verified information used by the second node is information obtained by the second node.
[0197] Further, the generation of the first verification parameter also needs to use the KDF. The KDF can be replaced by a hash algorithm. For example, the first verification parameter can be represented as HASHt, and the calculation method of HASHt is as follows:
[0198] HASHt = KDF(rk, the key agreement algorithm capability of the first node, the authentication mode indication, NONCEt, the content of the message T2, and the content of the message T4), wherein KDF is used to indicate the KDF algorithm used, and the input of KDF includes rk, the key agreement algorithm capability of the first node, the authentication mode indication, NONCE, the content of the message T2, and the content of the message T4, and the specific information is as follows: rk is the second key, the key agreement algorithm capability of the first node can be carried in the broadcast message, the authentication mode indication can be carried in the broadcast message, and NONCEt is the first freshness parameter. It should be understood that the order between the inputs of KDF and the number of parameters here are only examples, and in the specific implementation process, the number of information items included in the second to-be-verified information can be more or less, and the order of the input can also be designed in other ways.
[0199] In step S22, the second node sends the first verification parameter to the first node.
[0200] Correspondingly, the first node receives the first verification parameter. Optionally, the first verification parameter can be carried in the message T7. For example, the message T7 can be referred to as a session key confirmation response.
[0201] In step S23, the first node verifies the first verification parameter.
[0202] That is, the first node performs information verification based on the first verification parameter and the second to-be-verified information. For example, the second node generates a second check code based on the second to-be-verified information (including the second key and the information transmitted between the first node and the second node) obtained by itself, and compares the second check code with the first verification parameter to determine whether the value of the second to-be-verified information at the first node side is the same as the value of the second to-be-verified information at the second node side, so as to verify whether the second to-be-verified information is tampered with.
[0203] In a possible implementation, the second node-side information verification process is executed before the second node-side information verification process. The second node generates the first verification parameter based on the second to-be-verified information in the case of verifying the second verification parameter. Optionally, if the information verification is not successful, the second node can end the association process, or no longer respond to subsequent processes, or discard the information currently transmitted with the first node, and the like.
[0204] In a possible implementation, the first node can verify whether the first verification parameter is correct, and if the verification is successful, the first node opens the controlled port to allow the second node to access the corresponding resource.
[0205] In the embodiment shown in FIG. 5, the first node and the second node are independent of each other in the session key and the authentication key, guaranteeing high privacy of the session key and improving the communication security performance of the node. Further, the third node is used to authenticate the identity of the node, and the authentication key distributed by the third node is used to perform information verification with the second node, thereby improving the communication security performance of the node.
[0206] There are various possible implementations in the embodiment shown in FIG. 5. Two possible implementations are introduced below in combination with FIG. 14 and FIG. 15. It should be understood that some concepts and logics in FIG. 14 and FIG. 15 can be referred to the embodiment shown in FIG. 5.
[0207] Please refer to FIG. 14, which is a flow diagram of another communication method provided by the embodiment of the present application. Optionally, the method can be applied to a communication system, for example, the communication system shown in FIG. 4. The communication method shown in FIG. 14 can include one or more steps in steps S1401 to S1413. It should be understood that, for the convenience of description, the steps S1401 to S1413 are described in this order, and it is not intended to limit the execution in the above order. The embodiment of the present application does not limit the execution order, execution time, execution times, and the like of the one or more steps. Steps S1401 to S1413 are as follows:
[0208] Step S1401: The first node sends a broadcast message.
[0209] Correspondingly, the second node can receive the broadcast message, for example, a communication domain system message. The broadcast message carries the key negotiation algorithm capability of the first node and an authentication mode indication, which is used to indicate one of the following authentication modes: personal version, enterprise version-EAP authentication, enterprise version-certificate authentication, or enterprise version-self-defined authentication, and the like. The self-defined authentication is, for example, Portal authentication.
[0210] When the authentication mode is enterprise, i.e., the authentication mode indicates enterprise-EAP authentication, enterprise-certificate authentication, or enterprise-customized authentication.
[0211] The second node can request the association with the first node. In one possible implementation, when the authentication mode is enterprise, e.g., the authentication mode indicates enterprise-EAP authentication, enterprise-certificate authentication, or enterprise-customized authentication, the first node and the second node perform a security context negotiation procedure, but omit the calculation and verification of the authentication parameter in the security context negotiation procedure. Optionally, in the security context negotiation procedure, the first node and the second node negotiate to generate a session key. Further, the session key includes a session key for a signaling plane and a session key for a user plane. In some solutions, the first node and the second node initiate the encryption and integrity protection for the signaling plane.
[0212] In one possible instance, the first node performs the security context negotiation procedure as in steps S1402 and S1406. Specifically as follows:
[0213] Step S1402: The second node sends a message T1 to the first node. Accordingly, the first node receives the message T1 from the second node.
[0214] wherein the message T1 carries a first key derivation algorithm parameter and a first freshness parameter. The first key derivation algorithm parameter is exemplarily denoted as KEt, and the first freshness parameter is exemplarily denoted as NONCEt.
[0215] Step S1403: The first node sends a message T2 to the second node. Accordingly, the second node receives the message T2 from the first node.
[0216] wherein the message T2 carries a second key derivation algorithm parameter and a second freshness parameter. The second key derivation algorithm parameter is exemplarily denoted as KEt, and the second freshness parameter is exemplarily denoted as NONCEg.
[0217] Step S1404: The second node sends a message T3 to the first node. Accordingly, the first node receives the message T3 from the second node.
[0218] wherein the second node omits the calculation process related to the authentication parameter (exemplarily denoted as AUTH). For example, the authentication parameter field is not included in the message T3, or the authentication parameter field is a default value or a random value.
[0219] Step S1405: The first node sends a message T4 to the second node. Accordingly, the second node receives the message T4 from the first node.
[0220] The first node ignores the calculation process related to the authentication parameter (denoted by AUTH exemplarily). For example, the authentication parameter field is not included in the message T4, or the authentication parameter field is a default value or a random value.
[0221] Step S1406: The second node sends a message T5 to the first node. Correspondingly, the first node receives the message T5 from the second node.
[0222] As shown in FIG. 14, after the security context procedure, the authentication procedure is performed. The second node and the third node interact authentication messages, which are optionally forwarded by the first node. The authentication protection message procedure is determined based on the corresponding authentication mode, such as EAP authentication, certificate authentication, portal authentication, etc. The authentication mode is the authentication mode indicated by the authentication mode indication. Similarly, the first node can interact authentication messages with the third node, and the authentication protection message procedure is determined based on the corresponding authentication mode. The authentication mode is the authentication mode indicated by the authentication mode indication.
[0223] In a possible implementation, after the authentication passes, the second node and the third node respectively generate a second key based on the authentication protocol, as shown in FIG. 14.
[0224] Step S1407: The second node generates a second key.
[0225] For example, the second node generates a second key based on the authentication protocol. Similarly, the third node can generate a second key, for example, based on the authentication protocol. Further, the third node distributes the authentication key to the first node.
[0226] Step S1408: The first node receives the second key from the third node.
[0227] Optionally, the third node sends an authentication key distribution message to the first node, and the authentication key distribution message carries the second key rk.
[0228] Step S1409: The first node sends a message T6. Correspondingly, the second node receives the message T6 from the first node.
[0229] The message T6 carries a second check parameter (denoted by HASHg exemplarily), which is calculated by the first node based on the second key and the information transmitted between the first node and the second node. Exemplarily, the calculation method of HASHg is as follows:
[0230] HASHg=KDF(rk,NONCEg,content of message T1,content of message T3), and the related parameters are introduced in the foregoing embodiment shown in FIG. 5.
[0231] Step S1410: The second node verifies HASHg.
[0232] Optionally, the second node performs step S1411 if the HASHg is verified.
[0233] Step S1411: The second node sends a message T7. Accordingly, the first node receives the message T7 from the second node.
[0234] The message T7 carries a first verification parameter (exemplarily denoted as HASHt), which is calculated by the second node based on the second key and the information transmitted between the first node and the second node. Exemplarily, the HASHt is calculated as follows:
[0235] HASHt = KDF (rk, the key agreement algorithm capability of the first node, the authentication mode indication, NONCEt, the content of the message T2, the content of the message T4).
[0236] Step S1412: The first node verifies the HASHt.
[0237] Step S1413: The first node opens a controlled port to allow the second node to access the allowed resources.
[0238] Optionally, the controlled port is, for example, the first communication port, and the second node can access the resources based on the first communication port.
[0239] In the embodiment shown in FIG. 14, the first node and the second node will have the session key and the authentication key independent of each other, to ensure the high privacy of the session key. Further, the third node is used to authenticate the identity of the node, and the authentication key distributed by the third node is used to verify the information with the second node, to ensure the communication security of the first node.
[0240] Referring to FIG. 15, FIG. 15 is a flow diagram of another communication method provided by the embodiments of the present application. Optionally, the method can be applied to a communication system, for example, the communication system shown in FIG. 4. The communication method shown in FIG. 14 can include one or more steps of steps S1501 to S1513. It should be understood that, for the convenience of description, the steps S1501 to S1513 are described in this order, and it is not intended to limit the execution in the above order. The embodiments of the present application do not limit the execution order, execution time, execution times, etc. of the one or more steps. The steps S1501 to S1513 are as follows:
[0241] Step S1501: The first node sends a broadcast message.
[0242] Accordingly, the second node can receive the broadcast message. The broadcast message carries the key agreement algorithm capability of the first node.
[0243] The second node can request to associate with the first node, and the first node performs the security context negotiation procedure as in steps S1502 and S1506. Part of the content can refer to the description of steps S1402 to S1406 in FIG. 6 and FIG. 14, and the difference from steps S1402 to S1406 is that the authentication capability indication is carried in the message T1, and the authentication capability indication can indicate one or more of the following authentication manners: one or more of the personal version, the enterprise version-EAP authentication, the enterprise version-certificate authentication, the enterprise version-self-defined authentication, etc. The first node selects the authentication manner with the highest priority based on the authentication capability of the second node, the authentication capability of the G node and the preferred strategy. The authentication manner indication is carried in the message T2 to indicate the authentication manner selected by the first node.
[0244] As shown in FIG. 15, after the security context procedure, the authentication procedure is performed. The subsequent steps S1507 to S1513 can refer to steps S1407 to S1413.
[0245] The above describes the method of the embodiments of the present application in detail, and the following provides the device of the embodiments of the present application.
[0246] It should be understood that the device provided in the embodiments of the present application is logically divided into units, and all or part of the units can be integrated into a physical entity, or can be physically separated. In addition, the units in the device can be implemented in the form of processor calling software. For example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any one of the above methods or to realize the functions of each unit of the device, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is an internal memory of the device or an external memory of the device.
[0247] Alternatively, the units in the apparatus can be implemented in the form of hardware circuitry, and part or all of the units can be implemented through design of the hardware circuitry, which can be understood as one or more processors. For example, in one implementation, the hardware circuitry is an application-specific integrated circuit (ASIC) designed through logical relationship between elements in the circuitry to implement part or all of the units. For another example, in another implementation, the hardware circuitry is a programmable logic device (PLD) that can be implemented through a field programmable gate array (FPGA), which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured through a configuration file, so as to implement part or all of the units.
[0248] In the embodiments of the present application, each unit in the apparatus can be one or more processors (or processing circuitry) configured to implement the above methods, such as a CPU, a graphics processing unit (GPU), a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), a micro processor unit (MPU), a digital signal processor (DSP), an ASIC, an FPGA, or a combination of at least two of these processor forms.
[0249] In addition, each unit in the above apparatus can be integrated together in whole or in part, or can be independently implemented. In one implementation, the units are integrated together in the form of a system on a chip (SOC, or system-level chip). The SOC can include at least one processor for implementing any of the above methods or implementing the functions of each unit of the apparatus, and the at least one processor can be of different types, such as including a CPU and an FPGA, or containing a CPU and an artificial intelligence processor, or containing a CPU and a GPU, etc. The following lists several possible apparatuses.
[0250] Please refer to Fig. 16, which is a structural schematic diagram of a communication apparatus provided in an embodiment of the present application. Optionally, the communication apparatus 160 can be a standalone device, such as a node or the like. Alternatively, the communication apparatus 160 can also be a component, such as a chip or an integrated circuit, in a standalone device (e.g., a node). The communication apparatus 160 is configured to implement the communication method described above, such as the communication method in the embodiments of Fig. 5, Fig. 14, Fig. 16, and possible implementation manners thereof.
[0251] For example, the communication apparatus 160 includes a processing unit 1601 and a communication unit 1602. The processing unit 1601 is configured to implement one or more operations of processing, determining, generating, calculating, encrypting, decrypting, and the like, and the communication unit 1602 is configured to implement one or more operations of sending and receiving. It should be understood that the division of units here is merely illustrative, and in specific implementation, some units can be combined together, or one unit can be split into multiple units. For example, the processing unit 1601 can include an obtaining unit configured to obtain data from an upper layer, and a calculation unit configured to perform a calculation process.
[0252] In one possible design, the communication apparatus 160 is configured to implement the method on the first node side in the communication method described above.
[0253] In one possible implementation, the processing unit 1601 and the communication unit 1602 are configured to perform security context negotiation with the second node to obtain the first key. The communication unit 1602 is further configured to receive the second key from the third node. For details, refer to the description of the embodiments of Fig. 5, Fig. 14, and Fig. 15.
[0254] In another possible implementation, the communication unit 1602 is further configured to interact with the third node an authentication message, where the authentication message is used to authenticate the second node.
[0255] In another possible implementation, the communication unit 1602 is further configured to interact with the second node an authentication message, where the authentication message is used to authenticate the second node.
[0256] In another possible implementation, the communication unit 1602 is further configured to interact with the third node and the second node an authentication message.
[0257] In another possible implementation, the communication unit 1602 is further configured to broadcast the authentication mode indication.
[0258] In another possible implementation, the communication unit 1602 is further configured to receive the authentication capability indication from the second node, and send the authentication mode indication to the second node.
[0259] In yet another possible implementation, the communication unit 1602 is further configured to receive the first message from the second node and transmit a second message to the second node. The first message can be the message T1 described above, and the second message can be the message T2 described above.
[0260] In yet another possible implementation, the communication unit 1602 is further configured to receive a third message from the second node and transmit a fourth message to the second node. The third message can be the message T3 described above, and the fourth message can be the message T4 described above.
[0261] In yet another possible implementation, the communication unit 1602 is further configured to receive a first verification parameter from the second node, and the processing unit 1601 is further configured to verify the first verification parameter.
[0262] In yet another possible implementation, the processing unit 1601 is further configured to open the first communication port to allow the second node to access the resource if the verification of the first verification parameter is successful.
[0263] In yet another possible implementation, the processing unit 1601 is further configured to generate a second verification parameter based on the second key, the second freshness parameter, the first message and the third message, and the communication unit 1602 is further configured to transmit the second verification parameter to the second node.
[0264] In yet another possible design, the communication apparatus 160 is configured to implement the method on the second node side in the foregoing communication method.
[0265] In a possible implementation, the processing unit 1601 and the communication unit 1602 are configured to perform a security context negotiation with the first node to obtain the first key. The communication unit 1602 is further configured to interact with the third node or the first node an authentication message, and the processing unit 1601 is further configured to generate the second key based on an authentication protocol. For details, refer to the foregoing description, for example, the description of the embodiments shown in FIG. 5, FIG. 14 and FIG. 15.
[0266] In yet another possible implementation, the communication unit 1602 is further configured to receive a broadcast message from the first node.
[0267] In yet another possible implementation, the communication unit is further configured to transmit an authentication capability indication to the first node and receive an authentication mode indication from the first node.
[0268] In yet another possible implementation, the communication unit 1602 is further configured to transmit a first message to the first node and receive a second message from the first node. The first message can be the message T1 described above, and the second message can be the message T2 described above.
[0269] In a further possible implementation form of the second aspect, the communication unit 1602 is further configured to transmit a third message to the first node and to receive a fourth message from the first node. The third message can be the message T3 described above and the fourth message can be the message T4 described above.
[0270] In a further possible implementation form of the second aspect, the communication unit 1602 is further configured to receive a second verification parameter from the first node, and the processing unit 1601 is further configured to verify the second verification parameter. Further, the processing unit 1601 is further configured to verify the second verification parameter based on the second key, the second freshness parameter, the first message, the third message and the second verification parameter.
[0271] In a further possible implementation form of the second aspect, the processing unit 1601 is further configured to generate the first verification parameter based on the second key, a key agreement algorithm capability of the first node, the authentication mode indication, the first freshness parameter, the second message and the fourth message. The communication unit 1602 is further configured to transmit the first verification parameter to the first node.
[0272] Fig. 17 is a schematic diagram of a node according to an embodiment of the present application. The node 170 can be a stand-alone device, such as a node, or can be a component included in a stand-alone device, such as a chip, a software module, or an integrated circuit, etc. The node 170 can comprise at least one processor 1701 and a memory 1703. Optionally, it can further comprise a communication interface 1702. Further optionally, it can further comprise a connection line 1704, wherein the processor 1701, the communication interface 1702 and / or the memory 1703 are connected by the connection line 1704, and / or communicate with each other by the connection line 1704 to transfer control signals and / or data signals.
[0273] wherein:
[0274] The processor 1701 is a module that performs arithmetic operations and / or logical operations, and can specifically include one or more of the following modules: a filter, a modem, a power amplifier, a low noise amplifier (LNA), a baseband processor, a radio frequency processor, a radio frequency circuit, a central processing unit (CPU), an application processor (AP), a microcontroller unit (MCU), an electronic control unit (ECU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated Circuit (ASIC), an image signal processor (ISP), a digital signal processor (DSP), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), or a co-processor, etc.
[0275] The communication interface 1702 can be configured to provide information input or output for at least one processor, or to receive a signal transmitted from an external device and / or transmit a signal to an external device. For example, the communication interface 1702 can include an interface circuit. For example, the communication interface 1702 can include a wired link interface such as an Ethernet cable, and can also be a wireless link (Wi-Fi, Bluetooth, universal wireless transmission, vehicle-mounted short-range communication technology, and other short-range wireless communication technologies) interface. Optionally, the communication interface 1702 can also include a radio frequency transmitter, an antenna, etc. In the case where the communication interface 1702 includes an antenna, the number of antennas can be one or more.
[0276] As one possible design, if the node 170 is a standalone device, the communication interface 1702 can include a receiver and a transmitter. The receiver and the transmitter can be the same component or different components. When the receiver and the transmitter are the same component, the component can be referred to as a transceiver.
[0277] As yet another possible design, if the node 170 is a chip or a circuit, the communication interface 1702 can include an input interface and an output interface, which can be the same interface, or can be different interfaces.
[0278] Optionally, the functions of the communication interface 1702 can be implemented by a transceiver circuit or a dedicated chip of transceiver.
[0279] The memory 1703 is configured to provide a storage space, in which data such as an operating system and a computer program can be stored. The memory 1703 can be one or a combination of a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM).
[0280] It is to be understood that the functions and actions of the modules or units in the above-mentioned node 170 are only exemplary.
[0281] The functional units in the node 170 can be configured to implement the above-mentioned communication method, such as the communication method shown in the embodiments of FIG. 5, FIG. 14, FIG. 16, and possible implementation manners thereof. For example, the node 170 is configured to perform the method performed by the first node or the second node.
[0282] Optionally, the processor 1701 can be a processor specially configured to perform the above-mentioned method (for the sake of distinction, referred to as a special-purpose processor), or can be a processor configured to perform the above-mentioned method by invoking a computer program (for the sake of distinction, referred to as a special-purpose processor). Optionally, the at least one processor can include both a special-purpose processor and a general-purpose processor.
[0283] Optionally, in the case where the node 170 includes at least one memory 1703, if the processor 1701 implements the above-mentioned communication method by invoking a computer program, the computer program can be stored in the memory 1703.
[0284] The embodiments of the present application also provide a chip, which includes a logic circuit and a communication interface. The communication interface is configured to receive a signal or send a signal. The logic circuit is configured to receive a signal or send a signal through the communication interface. The chip is configured to implement the above-mentioned communication method, such as the communication method shown in the embodiments of FIG. 5, FIG. 14, FIG. 15, and possible implementation manners thereof.
[0285] The embodiments of the present application further provide a computer readable storage medium, wherein instructions are stored in the computer readable storage medium, and when the instructions are executed on at least one processor (or a communication device), the communication method described above, for example, the communication method and possible implementation manners shown in the embodiments of FIG. 5, FIG. 14, FIG. 15, etc.
[0286] The embodiments of the present application further provide a computer program product, which comprises computer instructions for implementing the communication method described above, for example, the communication method and possible implementation manners shown in the embodiments of FIG. 5, FIG. 14, FIG. 15, etc.
[0287] It should be noted that in the embodiments of the present application, the words such as "exemplarily" or "for example" are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplarily" or "for example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the words such as "exemplarily" or "for example" are intended to present the relevant concept in a specific manner.
[0288] In the embodiments of the present application, the names of information and devices are exemplarily named for the convenience of understanding the content of the present application, and in the specific implementation, the names can be designed in other ways. In addition, the names of the same thing can also be designed differently in different scenarios (for example, different communication layers).
[0289] In the present application, "at least one" means one or more, and "multiple" means two or more. "At least one" or the like means any combination of the items, including any combination of single item or multiple items.
[0290] For example, at least one of a, b, or c can represent a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or multiple. "And / or" describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects.
[0291] In addition, unless otherwise stated, the ordinal numbers "first", "second", "T1", "T2", etc. used in the embodiments of the present application are used to distinguish a plurality of objects, and are not used to limit the order, time sequence, priority or importance of the plurality of objects. For example, the first node and the second node are only used to facilitate the description of the nodes in different embodiments, and do not mean that the nodes have different operation, importance or structure.
[0292] In the above embodiments, according to the context, the term "when" can be interpreted to mean "if" or "after" or "in response to determining" or "in response to detecting". The above is only an optional embodiment of the present application and is not used to limit the present application. Any modification, equivalent replacement, improvement, etc. within the concept and principle of the present application shall be included in the protection scope of the present application.
[0293] A person of ordinary skill in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or by a program instructing relevant hardware, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.
Claims
1. A communication method characterized by comprising: The communication method is applied to a first node, and the communication method comprises: obtaining a first key through security context negotiation with a second node, the second node being a node requesting association with the first node, the first key being used for security protection of a session between the first node and the second node; receiving a second key from a third node, the third node being used for authentication of the second node, the second key being used for verification of information transmitted between the first node and the second node.
2. The communication method according to claim 1, characterized by, The method further comprises: interacting with the third node and / or the second node with an authentication message, the authentication message being used for authentication of the second node.
3. The communication method according to claim 2, wherein, Before the obtaining of the first key through security context negotiation with the second node, the method further comprises: broadcasting an authentication mode indication, the authentication mode indication being used for indicating a first authentication mode, the authentication message being related to the first authentication mode.
4. The communication method according to claim 2, characterized by, The method further comprises: receiving an authentication capability indication from the second node, the authentication capability indication being used for indicating authentication modes supported by the second node; sending an authentication mode indication to the second node, the authentication mode indication being used for indicating a first authentication mode, the first authentication mode being a highest-priority authentication mode among authentication modes supported by the first node and the second node, the authentication message being related to the first authentication mode.
5. The communication method according to any one of claims 1 to 3, characterized by, The authentication mode indication is used for indicating one of the following authentication modes: a personal version, an enterprise version-extensible authentication protocol (EAP) authentication, an enterprise version-certificate authentication, or an enterprise version-self-defined authentication.
6. The communication method according to any one of claims 1 to 5, characterized by, The obtaining of the first key through security context negotiation with the second node comprises: receiving a first message from the second node, the first message comprising a first key negotiation parameter, the first key being related to the first key negotiation parameter; sending a second message to the second node, the second message comprising a second key negotiation parameter, the first key being related to the second key negotiation parameter; receiving a third message from the second node, the third message being used for responding to the second message; sending a fourth message to the second node, the fourth message being used for indicating whether association between the first node and the second node is established.
7. The communication method according to claim 6, wherein, The second message further comprises a first authentication parameter field, the first authentication parameter field being used for carrying a first authentication parameter, a value of the first authentication parameter field being a default value or a random value.
8. The communication method according to claim 6 or 7, characterized by, The third message comprises a second authentication parameter field, the second authentication parameter field being used for carrying a second authentication parameter, the first node does not perform a verification process related to a value of the second authentication parameter field, and / or the value of the second authentication parameter field is a default value or a random value.
9. The communication method according to any one of claims 6-8, characterized by, The method further comprises: receiving a first verification parameter from the second node, the first verification parameter being related to the second key, a key negotiation algorithm capability of the first node, an authentication mode indication, the second message, the fourth message, and a first fresh parameter, the first fresh parameter being included in the first message; verifying the first verification parameter.
10. The communication method according to claim 9, wherein, After verifying the first check parameter, the method further comprises: In case of successful verification, opening the first communication port to allow the second node to access resources.
11. The communication method according to any one of claims 6-10, characterized by, The method further comprises: Based on the second key, a second fresh parameter, the first message and the third message, generating a second check parameter, the second fresh parameter being included in the second message; Sending the second check parameter to the second node, the second check parameter being used to check the second fresh parameter, the first message and the third message.
12. A communication method characterized by comprising: The communication method is applied to a second node, and the communication method comprises: Carrying out security context negotiation with a first node to obtain a first key, the first node being a node requesting association for the second node, the first key being used to protect a session between the first node and the second node; Interacting with an authentication message with the third node or the first node, the first node being connected with the third node, the authentication message being related to an authentication protocol, the third node being used to authenticate the second node; Based on the authentication protocol, generating a second key, the second key being used to check information transmitted by the first node and the second node.
13. The communication method according to claim 12, wherein, Before the security context negotiation with the first node to obtain the first key, the method further comprises: Receiving a broadcast message from the first node, the broadcast message comprising an authentication mode indication, the authentication mode indication being used to indicate a first authentication mode, the authentication message being related to the first authentication mode.
14. The communication method according to claim 12, wherein, Before the authentication message is interacted with the third node or the first node, the method further comprises: Sending an authentication capability indication to the first node, the authentication capability indication being used to indicate authentication modes supported by the second node; Receiving an authentication mode indication from the first node, the authentication mode indication being used to indicate a first authentication mode, the first authentication mode being the highest priority authentication mode among authentication modes supported by the first node and the second node, the authentication message being related to the first authentication mode.
15. The communication method according to any one of claims 12-14, characterized by, The authentication mode indication is used to indicate one of the following authentication modes: personal version, enterprise version-EAP authentication, enterprise version-certificate authentication or enterprise version-self-defined authentication.
16. The communication method according to any one of claims 12-15, characterized by, The security context negotiation with the second node to obtain the first key comprises: Sending a first message to the first node, the association request message comprising a first key negotiation parameter, the first key being related to the first key negotiation parameter; Receiving a second message from the first node, the second message comprising a second key negotiation parameter, the first key being related to the second key negotiation parameter, Sending a third message to the first node, the third message being used to respond to the second message; Receiving a fourth message from the first node, the fourth message being used to indicate whether association between the first node and the second node is established.
17. The communication method of claim 16, wherein, The second message further comprises a first authentication parameter field, the first authentication parameter field being used to carry a first authentication parameter, The second node does not perform a verification procedure related to the value of the first authentication parameter field, and / or the value of the first authentication parameter field is a default value or a random value.
18. The communication method according to claim 16 or 17, characterized by, The third message includes a second authentication parameter field, the second authentication parameter field being used to carry a second authentication parameter, and the value of the second authentication parameter field being a default value or a random value.
19. The communication method according to any one of claims 16-18, characterized by, The method further includes: receiving a second verification parameter from the first node, the second verification parameter being related to a second fresh parameter, the first message and the third message, the second fresh parameter being included in the second message; verifying the second verification parameter.
20. The communication method according to claim 19, wherein, The method further includes: generating a first verification parameter based on the second key, a key agreement algorithm capability of the first node, an authentication mode indication, the second message, the fourth message and the first fresh parameter; sending the first verification parameter to the first node.
21. The communication method according to claim 20, wherein, The step of sending the first verification parameter to the first node is performed in the case that the verification of the second verification parameter is successful.
22. A communications device, characterized by The communication device includes a processing unit and a communication unit, the communication device being configured to implement the method of any one of claims 1-11, or to implement the method of any one of claims 12-21.
23. A node, characterized by The node includes a processor and a memory, The memory is configured to store computer instructions, The processor is configured to invoke the computer instructions stored in the memory, so that the method of any one of claims 1-11 is performed, or the method of any one of claims 12-21 is performed.
24. A communication system, characterized by The communication system includes a first node and a second node, The first node is configured to perform the method of any one of claims 1-11, The second node is configured to perform the method of any one of claims 12-21.
25. A computer readable storage medium, characterized in that, The computer readable storage medium is configured to store computer instructions; When the instructions are executed by the processor, the method of any one of claims 1-11 is performed, or the method of any one of claims 12-21 is performed.
Citation Information
Patent Citations
Key distribution method and device, mobile terminal, communication equipment and storage medium
CN110536289A
Access authentication method, related device, equipment and readable storage medium
CN115150110A
Key negotiation method and device, medium and electronic equipment
CN115296803A
Data processing method and equipment thereof
CN115484038A
Wireless network switching method and device
US20220417750A1