Data security processing method, communication device, communication system, storage medium and program product
By generating a second key based on a shared key, the risk to communication security between the terminal and the service network during the initial authentication process is resolved, enabling early security protection and improving the security of the authentication process.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2024-10-24
- Publication Date
- 2026-04-30
AI Technical Summary
During the initial authentication process of a terminal, there is a risk that messages between the terminal and the service network may be tampered with or eavesdropped on by attackers, and existing technologies cannot effectively protect communication security.
By generating a second key based on a shared key, and using the first key to generate the second key, the communication security between the terminal and the first node is protected, ensuring that security protection is established as early as possible during the initial authentication process.
This reduces the likelihood of DoS attacks during the initial authentication of a terminal, thus improving the security of the initial authentication process.
Smart Images

Figure CN2024127118_30042026_PF_FP_ABST
Abstract
Description
Data security processing methods, communication equipment, communication systems, storage media and software products Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to data security processing methods, communication equipment, communication systems, storage media, and program products. Background Technology
[0002] To ensure the security of communication between terminals and the network, mobile communication networks have introduced two security mechanisms: Access Stratum (AS) security and Non-Access Stratum (NAS) security. After the network device successfully authenticates the terminal for the first time, it activates NAS message security protection by sending a NAS Security Mode Command (SMC) message to the terminal, thus establishing NAS security. AS security is established after NAS security is established.
[0003] During the initial authentication process, messages between the terminal and the service network are unprotected, making them vulnerable to tampering or eavesdropping by attackers. How to protect the security of messages between the terminal and the service network during this initial authentication process remains to be solved.
[0004] Summary of the Invention
[0005] This disclosure provides a data security processing method, communication device, communication system, storage medium, and program product.
[0006] According to a first aspect of the present disclosure, a data security processing method is provided, wherein the method is executed by a first node, and the method includes: generating a second key based at least on a first key; the first key is provided by a second node, and the first key is a shared key generated by the second node during the initial authentication of a terminal; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
[0007] According to a second aspect of the present disclosure, a data security processing method is provided, wherein the method is executed by a terminal, and the method includes: generating a second key based at least on a first key; the first key is a shared key generated by the terminal during initial authentication; and the second key is used at least during the initial authentication of the terminal to protect the communication security between the terminal and a first node.
[0008] According to a third aspect of the present disclosure, a data security processing method is provided, wherein the method is executed by a second node, the method comprising: sending a fourth message to a first node; the fourth message being a response message to a terminal authentication request message, the fourth message including a first key, the first key being a shared key generated by the second node during the initial authentication of the terminal, the first key being used by the first node to generate a second key; the second key being used at least during the initial authentication of the terminal to protect the communication security between the terminal and the first node.
[0009] According to a fourth aspect of the present disclosure, a data security processing method is provided, wherein the method is executed by a communication system, the method comprising: a first node generating a second key based at least on a first key; the first key being provided by a second node, the first key being a shared key generated by the second node during the initial authentication of a terminal; the second key being used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal; the first node sending a first message to the terminal; the first message being used to trigger the terminal to generate the second key; and the terminal generating the second key based at least on the first key.
[0010] According to a fifth aspect of the present disclosure, a communication device is provided, wherein the communication device performs the data security processing method provided by the first aspect, the second aspect, or the third aspect.
[0011] According to a sixth aspect of the present disclosure, a communication system is provided, wherein the communication system includes a terminal and a first node, the first node being configured to implement the data security processing method provided in the first aspect, and the terminal being configured to implement the data security processing method provided in the second aspect.
[0012] According to a seventh aspect of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the data security processing method provided in the first, second, or third aspect.
[0013] According to an eighth aspect of the present disclosure, a computer program is provided that includes code, which, when executed by a processor, implements the data security processing method provided by the first, second, or third aspect.
[0014] The technical solution provided in this disclosure is advantageous in generating a second key from a shared key (i.e., a first key) generated during the initial authentication of the terminal. This allows a second key to be generated based on the first key to protect the communication security between the terminal and the first node once the first key is shared between the first node and the terminal during the initial authentication. The second key is used to protect the communication security between the terminal and the first node as early as possible during the initial authentication of the terminal, thereby reducing the possibility of DoS attacks during the initial authentication of the terminal and improving the security of the initial authentication process of the terminal.
[0015] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the embodiments of this disclosure. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the embodiments of the invention.
[0017] Figure 1A is a schematic diagram of the architecture of a communication system according to an exemplary embodiment;
[0018] Figure 1B is a schematic diagram illustrating a protection process for an initial NAS message according to an exemplary embodiment;
[0019] Figure 1C is a schematic diagram illustrating the startup process of the initial authentication process of a terminal according to an exemplary embodiment;
[0020] Figure 1D is a schematic diagram of the initial authentication process of a terminal according to an exemplary embodiment;
[0021] Figure 1E is a schematic diagram illustrating the initial authentication process of a terminal according to an exemplary embodiment.
[0022] Figure 2A is an interactive schematic diagram of a data security processing method according to an exemplary embodiment;
[0023] Figure 2B is an interactive schematic diagram of a data security processing method according to an exemplary embodiment;
[0024] Figure 3 is an interactive schematic diagram of a data security processing method according to an exemplary embodiment;
[0025] Figure 4A is a schematic diagram of an authentication process based on EAP-AKA′ according to an exemplary embodiment;
[0026] Figure 4B is a schematic diagram of an authentication process based on 6G AKA according to an exemplary embodiment;
[0027] Figure 5A is a schematic diagram of the structure of a network device according to an exemplary embodiment;
[0028] Figure 5B is a schematic diagram of the structure of a terminal according to an exemplary embodiment;
[0029] Figure 5C is a schematic diagram of the structure of a network device according to an exemplary embodiment;
[0030] Figure 6A is a schematic diagram of the structure of a communication device according to an exemplary embodiment;
[0031] Figure 6B is a schematic diagram of the structure of a chip according to an exemplary embodiment. Detailed Implementation
[0032] This disclosure provides a data security processing method, communication device, communication system, storage medium, and program product.
[0033] In a first aspect, embodiments of this disclosure provide a data security processing method, wherein the method is executed by a first node, and the method includes: generating a second key based at least on a first key; the first key is provided by a second node, and the first key is a shared key generated by the second node during the initial authentication of the terminal; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
[0034] In the above embodiments, the first node obtains a first key from the second node and generates a second key based on the first key to protect the communication security between the terminal and the first node. Since the first key is a shared key generated by the second node during the initial authentication of the terminal, once the first node obtains the first key during the initial authentication process, it can use the second key generated based on the first key to protect the communication security between the terminal and the first node. Utilizing the second key to protect the communication security between the terminal and the first node as early as possible during the initial authentication process reduces the likelihood of DoS attacks during the initial authentication of the terminal and improves the security of the initial authentication process.
[0035] In conjunction with some embodiments of the first aspect, in some embodiments, generating a second key based at least on a first key includes one of the following: generating a second key based on a first key and a first security algorithm; wherein the first security algorithm is determined by a first node based on first information and second information, the first information being used to indicate the security algorithm supported by the terminal; the second information being used to indicate the security algorithm supported by the first node; generating a second key based on a third key and the first security algorithm; the third key being generated by the first node based on the first key.
[0036] The above embodiments provide two schemes for generating the second key. In one scheme, the first node generates the second key based on the first key and the first security algorithm. This takes into account the security capability matching between the terminal and the first node when generating the second key, ensuring that the second key is applicable to both the terminal and the first node. Alternatively, the first node can generate a third key based on the first key, and then generate the second key based on the third key and the first security algorithm. This allows for the generation of a second key to protect communication security between the terminal and the first node during the terminal's initial authentication, while also meeting the requirements for security isolation between networks.
[0037] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: generating a third key based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0038] In the above embodiments, since the third information is used to identify the security context derived from the first key, the first node generates the third key based on the first key and the third information. On the one hand, generating the second key based on the third key can meet the requirements of security isolation between networks. On the other hand, the first node can directly use the third information created during the initial authentication process of the terminal to generate the third key, which not only ensures the relevance of the security context but also improves the utilization rate of communication resources.
[0039] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: sending a first message to the terminal; the first message is used to trigger the terminal to generate a second key.
[0040] In the above embodiments, after the first node generates the second key, the first node can send a first message to the terminal to trigger the terminal to generate the second key, thereby enabling the terminal and the first node to establish a shared security context based on the second key. This allows the communication security between the terminal and the first node to be protected as early as possible during the terminal's first authentication process based on the security context between the terminal and the first node, thereby improving the security of the terminal's first authentication process.
[0041] In conjunction with some embodiments of the first aspect, in some embodiments, the first message is used by the terminal to determine the first security algorithm, and the first security algorithm is used by the terminal to generate the second key.
[0042] In the above embodiments, the first node sends a first message to the terminal to inform the terminal of the first security algorithm selected by the first node, thereby completing the security algorithm negotiation between the first node and the terminal. This enables the terminal to generate a second key based on the negotiated first security algorithm and the first key, so as to use the second key to protect the communication security between the terminal and the first node as early as possible during the terminal's first authentication process, thereby improving the security of the terminal's first authentication process.
[0043] In conjunction with some embodiments of the first aspect, in some embodiments, the first message is a message whose integrity is protected by the first node using a second key.
[0044] In the above embodiments, the first message is a message whose integrity is protected by the first node using the second key. This allows the terminal to verify the integrity of the first message after generating the second key, thereby verifying the establishment of a shared security context between the terminal and the first node and improving the success rate of establishing a shared security context between the terminal and the first node.
[0045] In conjunction with some embodiments of the first aspect, in some embodiments, the first message includes at least one of the following: third information for identifying a security context derived based on the first key; fourth information for identifying a first security algorithm; and fifth information for indicating a first verification value. The first verification value is a message verification value obtained by the first node using the second key to perform integrity protection on the first message, and the first verification value is used by the terminal to perform integrity verification on the first message.
[0046] In the above embodiments, the first message may include at least one of third information, fourth information, and fifth information. The third information carried in the first message enables the terminal to learn the generation parameters of the intermediate key used to generate the second key, thereby enabling the terminal to generate the third key using the third information; and / or, the fourth information enables the terminal to learn the first security algorithm selected by the first node, completing the security algorithm negotiation between the terminal and the first node; and / or, the fifth information carried in the first message enables the terminal to determine whether the first message has been tampered with after verifying the integrity of the first message based on the generated second key.
[0047] In conjunction with some embodiments of the first aspect, in some embodiments, the first message includes: first information for indicating the security algorithm supported by the terminal; the first information is also used by the terminal to determine whether the security algorithm supported by the terminal sent to the first node has been tampered with.
[0048] In the above embodiments, the first message sent by the first node may further include first information, so that after receiving the first message, the terminal can determine whether the terminal-supported security algorithm sent to the first node before the establishment of communication security has been tampered with, based on the security algorithm indicated by the first information and the security algorithm it supports stored in the terminal, so as to ensure that the terminal and the first node can effectively negotiate the security algorithm.
[0049] In conjunction with some embodiments of the first aspect, in some embodiments, the first message further includes one of the following: a sixth message, used to indicate that the second node has successfully authenticated the terminal's identity; a seventh message, used to request the terminal to authenticate with the network; the seventh message includes: a first random number and an authentication token.
[0050] In the above embodiments, during the initial authentication of the terminal based on different authentication algorithms, the first node may also carry sixth or seventh information in the first message, so as to continue to execute the corresponding authentication process while triggering the terminal to generate a second key using the first message.
[0051] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: receiving a second message sent by a terminal; the second message is a message sent by the terminal after successfully verifying the integrity of the first message, and the second message is a message protected by the terminal using a second key.
[0052] In the above embodiments, since the second message is sent by the terminal after the integrity verification of the first message is successful, the second message can be used to enable the first node that receives the second message to determine that the security context shared between the first node and the terminal has been successfully established.
[0053] In conjunction with some embodiments of the first aspect, in some embodiments, the second message includes: an eighth message, which is used to indicate a first authentication response value; the first authentication response value is used by the first node to authenticate the terminal; the first authentication response value is generated by the terminal based on a first random number after the authentication token is successfully verified.
[0054] In the above embodiments, during the initial authentication process of the terminal, the first node receives a second message including the eighth information. On the one hand, the first node can use the first authentication response value indicated by the eighth information to continue to execute the subsequent authentication process to complete the initial authentication of the terminal. On the other hand, the first node determines that the security context shared between the first node and the terminal has been successfully established based on the second message, and in the subsequent authentication process, the security of communication between the terminal and the first node is guaranteed based on the security context.
[0055] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0056] The third message is sent by the receiving terminal; the third message is sent by the terminal after the integrity verification of the first message fails, and the third message is used to trigger the first node to resend the first message to the terminal.
[0057] In the above embodiments, since the third message is a message sent by the terminal when the integrity verification of the first message fails, the third message can be used to make the first node that receives the third message fail to determine the security mode command process initiated between the first node and the terminal, thereby triggering the first node to resend the first message to the terminal to re-initiate the security mode command process.
[0058] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: receiving a fourth message sent by a second node; the fourth message is a response message to a terminal authentication request message, and the fourth message includes a first key.
[0059] In the above embodiments, the first key is transmitted by reusing the response message (i.e. the fourth message) of the terminal authentication request message sent by the second node to the first node during the first authentication process of the terminal. This allows the first node to generate a second key based on the first key and use the second key to protect the communication security between the terminal and the first node as early as possible during the first authentication of the terminal.
[0060] In conjunction with some embodiments of the first aspect, in some embodiments, the fourth message includes an authentication vector; the authentication vector is used for the terminal to authenticate its identity with the network, and the authentication vector includes a first key.
[0061] In the above embodiments, the first key is carried in the fourth message, so that after receiving the fourth message, the first node can, on the one hand, perform identity authentication with the terminal based on the authentication vector and continue the subsequent authentication process; and on the other hand, generate a second key based on the first key, so as to protect the communication security between the terminal and the first node in the subsequent authentication process.
[0062] Secondly, embodiments of this disclosure provide a data security processing method, wherein the method is executed by a terminal, and the method includes: generating a second key based at least on a first key; the first key is a shared key generated by the terminal during initial authentication; the second key is used at least to protect the communication security between the terminal and a first node during the terminal's initial authentication.
[0063] In the above embodiments, the terminal can generate a second key based on the first key to protect the communication security between the terminal and the first node. Since the first key is a shared key generated by the terminal during the initial authentication, once the first node and the terminal share the first key during the initial authentication, the second key generated based on the first key can be used to protect the communication security between the terminal and the first node, thus protecting the communication security between the terminal and the first node as early as possible during the initial authentication.
[0064] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: receiving a first message sent by a first node, wherein the first message triggers a terminal to generate a second key.
[0065] In conjunction with some embodiments of the second aspect, in some embodiments, the first message is used by the terminal to determine the first security algorithm, and the first security algorithm is used by the terminal to generate the second key.
[0066] In conjunction with some embodiments of the second aspect, in some embodiments, the second key is generated at least based on the first key, including one of the following: generating the second key based on the first key and the first security algorithm; generating the second key based on the third key and the first security algorithm; the third key is generated by the first node based on the first key.
[0067] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: generating a third key based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0068] In conjunction with some embodiments of the second aspect, in some embodiments, the first message is a message whose integrity is protected by the first node using the second key.
[0069] In conjunction with some embodiments of the second aspect, in some embodiments, the first message includes at least one of the following: third information for identifying a security context derived based on the first key; fourth information for identifying a first security algorithm; and fifth information for indicating a first verification value. The first verification value is a message verification value obtained by the first node using the second key to perform integrity protection on the first message, and the first verification value is used by the terminal to perform integrity verification on the first message.
[0070] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: determining a second verification value; the second verification value is a message verification value obtained by the terminal using a second key to perform integrity protection on the first message; and determining the integrity verification result of the first message based on the second verification value and the first verification value; wherein the first message includes fifth information.
[0071] In the above embodiments, the terminal can use the generated second key to perform integrity protection on the received first message to obtain a second verification value, and determine the integrity verification result of the first message based on the comparison between the second verification value and the first verification value, thereby determining whether the first message has been tampered with.
[0072] In conjunction with some embodiments of the second aspect, in some embodiments, the first message includes first information, which is used to indicate the security algorithm supported by the terminal; the first information is used by the terminal to determine whether the security algorithm supported by the terminal sent to the first node has been tampered with.
[0073] In conjunction with some embodiments of the second aspect, in some embodiments, the first message further includes one of the following: a sixth message, used to indicate that the second node has successfully authenticated the terminal's identity; a seventh message, used to request the terminal to authenticate with the network; the seventh message includes: a first random number and an authentication token.
[0074] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: sending a second message to a first node; the second message is a message sent by the terminal after successfully verifying the integrity of the first message, and the second message is a message protected by the terminal using a second key.
[0075] In conjunction with some embodiments of the second aspect, in some embodiments, the second message includes: an eighth message, which is used to indicate a first authentication response value; the first authentication response value is used by the first node to authenticate the terminal; the first authentication response value is generated by the terminal based on a first random number after the authentication token is successfully verified.
[0076] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0077] Send a third message to the first node; the third message is sent by the terminal after the integrity verification of the first message fails, and the third message is used to trigger the first node to resend the first message to the terminal.
[0078] Thirdly, this disclosure provides a data security processing method, wherein the method is executed by a second node, and the method includes: sending a fourth message to a first node; the fourth message is a response message to a terminal authentication request message, the fourth message includes a first key, the first key is a shared key generated by the second node during the initial authentication of the terminal, the first key is used by the first node to generate a second key; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
[0079] In the above embodiment, the second node sends the first key to the first node by reusing the response message (i.e. the fourth message) of the terminal authentication request message sent by the second node to the first node during the first authentication process of the terminal. This allows the first node to generate a second key based on the first key and use the second key to protect the communication security between the terminal and the first node as early as possible during the first authentication of the terminal.
[0080] In conjunction with some embodiments of the third aspect, in some embodiments, the fourth message includes an authentication vector used by the terminal to authenticate itself with the network.
[0081] Fourthly, embodiments of this disclosure provide a data security processing method, which is executed by a communication system. The method includes: a first node generating a second key based at least on a first key; the first key is provided by a second node and is a shared key generated by the second node during the initial authentication of the terminal; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal; the first node sending a first message to the terminal; the first message triggering the terminal to generate the second key; and the terminal generating the second key based at least on the first key.
[0082] In conjunction with some embodiments of the fourth aspect, in some embodiments, the method further includes:
[0083] The second node sends a fourth message to the first node; the fourth message is a response message to the terminal authentication request message, and the fourth message includes the first key.
[0084] Fifthly, embodiments of this disclosure provide a communication device, wherein the communication device performs the data security processing method described in the optional implementations of the first, second, or third aspects.
[0085] In a sixth aspect, embodiments of this disclosure provide a communication system, wherein the communication system includes a terminal and a first node, the first node being configured to implement the data security processing method described in the optional implementation of the first aspect, and the terminal being configured to implement the data security processing method described in the optional implementation of the second aspect.
[0086] In conjunction with some embodiments of the sixth aspect, in some embodiments, the communication system further includes a second node configured to implement the data security processing method described in the optional implementation of the third aspect.
[0087] In a seventh aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the data security processing method described in the optional implementations of the first, second, or third aspects.
[0088] Eighthly, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the data security processing method described in the optional implementations of the first, second, or third aspects.
[0089] Ninthly, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the data security processing method described in optional implementations of the first, second, or third aspects.
[0090] It is understood that the aforementioned communication devices, communication systems, storage media, program products, etc., are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0091] This disclosure provides a data security processing method, a communication device, a communication system, a storage medium, and a program product. In some embodiments, the terms "data security processing method" and "information processing method," "information transmission method," etc., can be used interchangeably.
[0092] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0093] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0094] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0095] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0096] In the embodiments disclosed herein, "multiple" refers to two or more.
[0097] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0098] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "A in one case, B in another", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0099] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.
[0100] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0101] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0102] In some embodiments, terms such as “…”, “determine…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably.
[0103] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.
[0104] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.
[0105] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0106] In some embodiments, devices, etc., can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as “device”, “equipment”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.
[0107] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
[0108] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.
[0109] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.
[0110] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0111] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0112] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0113] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0114] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0115] Figure 1A is a schematic diagram of the architecture of a communication system according to an exemplary embodiment.
[0116] As shown in Figure 1A, the communication system 100 includes a terminal 101 and a network device 102. In one embodiment, the network device 102 may include at least one of an access network device and a core network device.
[0117] In some embodiments, terminal 101 includes, for example, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home, but is not limited thereto.
[0118] In some embodiments, the access network device may be a node or device that connects a terminal to a wireless network. The access network device may include at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system, but is not limited thereto.
[0119] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0120] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0121] In some embodiments, a core network device may be a single device, including one or more network elements, or it may be multiple devices or a group of devices, each including one or more network elements. Network elements may be virtual or physical. The core network may include at least one of the following: Evolved Packet Core (EPC), 5G Core Network (5GCN), Next Generation Core (NGC), and 6G Core (6GC).
[0122] In some embodiments, the first node and the second node may be core network devices.
[0123] In some embodiments, the first node and the second node can be different network elements of the core network device.
[0124] In some embodiments, the first node can be used to perform NAS layer security negotiation and protection with the terminal.
[0125] In some embodiments, the first node can be used to configure a root key for secure communication between NFs and terminals in the protection service network.
[0126] In some embodiments, the name of the first node is not specifically limited. For example, it may be a Security Anchor Function (SEAF), a Communication Security Anchor Function, or a Communication Key Configuration Function.
[0127] In some embodiments, the second node can be used to provide terminal authentication services.
[0128] In some embodiments, the second node is used to authenticate the terminal based on configuration parameters or subscription parameters between the home network and the terminal.
[0129] In some embodiments, the name of the second node is not specifically limited; for example, it may be the Authentication Server Function (AUSF), the authentication service function, etc.
[0130] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions provided in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in this disclosure are also applicable to similar technical problems.
[0131] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1A, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1A are illustrative. The communication system may include all or some of the main bodies in FIG1A, or it may include other main bodies outside of FIG1A. The number and form of each main body are arbitrary. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0132] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0133] In some embodiments, messages between a terminal and the service network in a 5G system are only protected after NAS security is established through the NAS SMC process. As shown in FIG1B, FIG1B is a schematic diagram of an initial NAS message protection process according to an exemplary embodiment. After the Authentication Management Function (AMF) successfully authenticates the terminal (i.e., step 2a of FIG1B), the AMF initiates the NAS SMC process. This means that during the initial authentication, including 5G EAP-AKA′ and 5G AKA, messages between the terminal and the service network are unprotected. As shown in FIG1C, FIG1C is a schematic diagram of the initiation process of the initial authentication process of a terminal according to an exemplary embodiment. As shown in FIG1D, FIG1D is a schematic diagram of the first authentication process of a terminal according to an exemplary embodiment. The initial authentication process shown in FIG1D is an EAP-AKA′-based initial authentication process. As shown in FIG1E, FIG1E is a schematic diagram of the second initial authentication process of a terminal according to an exemplary embodiment. The initial authentication process shown in FIG1E is an AKA-based initial authentication process. In Figures 1C, 1D, and 1E, messages between the terminal and the Security Anchor Function (SEAF) are not protected.
[0134] In some embodiments, because messages between the terminal and the service network are unprotected, an attacker can launch a denial-of-service (DoS) attack by tampering with the messages, causing the terminal's initial authentication to fail.
[0135] In some embodiments, in 6G networks, in order to improve the security level based on 5G security mechanisms, it is necessary to study how to protect messages between the terminal and the service network as early as possible during the initial authentication process, rather than protecting messages between the terminal and the service network after the initial authentication is successful, in order to reduce possible DoS attacks during the initial authentication process.
[0136] This disclosure provides a data security processing method, communication device, communication system, storage medium, and program product, so as to enable data security processing based on key K during the initial authentication of a terminal. SEAF Initiate the NAS / SEAF SMC process to establish security between the endpoint and the service network. Once key K is shared between the endpoint and SEAF... SEAF SEAF can then initiate a NAS / SEAF SMC process to establish NAS / SEAF security between the endpoint and SEAF. Due to K SEAF It is exported during the initial authentication of the terminal, therefore it can be based on K. SEAFProtect the communication security between the terminal and the service network through NAS / SEAF security as early as possible during the initial authentication process of the terminal.
[0137] Figure 2A is an interactive schematic diagram illustrating a data security processing method according to an exemplary embodiment. As shown in Figure 2A, this disclosure relates to a data security processing method for a communication system 100, the method comprising:
[0138] Step S2101: The second node sends the fourth message to the first node.
[0139] In some embodiments, the first node receives a fourth message sent by the second node.
[0140] In some embodiments, the fourth message is used to trigger the first node to generate the second key.
[0141] In some embodiments, the fourth message can be used to trigger the first node to initiate a security mode negotiation with the terminal.
[0142] In some embodiments, the fourth message may be a response message to a terminal authentication request message. This terminal authentication request message may be a message sent by the first node to the second node during the second node's initial authentication of the terminal. In one embodiment, the terminal authentication request message is used to request the network to authenticate the terminal.
[0143] In some embodiments, the fourth message may include the first key.
[0144] In some embodiments, the first key may be a shared key generated during the initial authentication of the terminal by the second node. In one example, the first key may be K. SEAF .
[0145] In some embodiments, the first key can be used by the first node to generate the second key.
[0146] In some embodiments, before the second node sends the fourth message to the first node, the terminal may send a seventh message to the first node. Here, the seventh message may be used by the terminal to request registration with the network; for example, the seventh message may be a registration request message.
[0147] In some embodiments, the seventh message may be a message transmitted based on the N1 interface.
[0148] In some embodiments, the seventh message may include terminal identification information. In one embodiment, the terminal identification information may be any information capable of identifying the terminal. For example, information that can uniquely identify the terminal, such as the International Mobile Subscriber Identification Number (IMSI), Subscriber Permanent Identifier (SUPI), International Mobile Equipment Identity (IMEI), 5G Globally Unique Temporary Identifier (GUTI), and Network Access Identifier (NAI).
[0149] In some embodiments, after receiving the seventh message, the first node may send a terminal authentication request message to the second node. In some embodiments, the terminal authentication request message is used to request the second node to perform an authentication process. In one embodiment, the terminal authentication request message may include terminal identification information and service network name.
[0150] In some embodiments, after receiving a terminal authentication request message from the first node, the second node may send a terminal authentication information retrieval request message to the third node. In some embodiments, the terminal authentication information retrieval request message may be used to request the third node to generate an authentication vector. In one embodiment, the third node may be a Unified Data Management (UDM), ARDF, etc.
[0151] In some embodiments, after receiving a terminal authentication information acquisition request message, the third node may select an authentication method and generate an authentication vector based on the authentication method.
[0152] In some embodiments, the authentication method may include: the Extensible Authentication Protocol-Authentication Key Agreement (EAP-AKA) method and the Authentication and Key Agreement (AKA) method, etc.
[0153] In some embodiments, after the third node generates the authentication vector, it can send a terminal authentication information retrieval response message to the second node. This response message may include the authentication vector and indication information. The indication information may include one of the following: first indication information, used to indicate that the authentication vector is applied during the initial authentication process based on the first authentication method; or second indication information, used to indicate that the authentication vector is applied during the initial authentication process based on the second authentication method. In one embodiment, after the third node generates the authentication vector based on the selected authentication method, the authentication vector can be applied during the initial authentication process based on that selected authentication method. If the authentication vector is generated based on the first authentication method, the terminal authentication information retrieval response message may include the first indication information. If the authentication vector is generated based on the second authentication method, the response message may include the second indication information.
[0154] In one embodiment, the first authentication method may be the AKA method, the EAP-Transport Layer Security (TLS) method, etc.
[0155] In one embodiment, the second authentication method may be the EAP-AKA' method, the EAP-Subscriber Identity Module (SIM) method, etc.
[0156] In some embodiments, the authentication vector may include: a first authentication vector and a second authentication vector, wherein the first authentication vector is generated based on a first authentication method and the second authentication vector is generated based on a second authentication method.
[0157] In one embodiment, the first authentication vector is generated based on the AKA method and may include a first random number, an authentication token, a third authentication response value, and a fourth key. In one embodiment, the third authentication response value may be XRES*.
[0158] In one embodiment, the second authentication vector is generated based on the EAP-AKA' method, and the second authentication vector may include a second random number, an authentication token, and a fourth authentication response value. In one embodiment, the fourth authentication response value may be XRES.
[0159] In some embodiments, after receiving a terminal authentication information acquisition response message containing a first authentication vector, the second node can determine a fourth key and generate a first key based on the fourth key. In some embodiments, the fourth key is a shared key between the terminal and the second node. In one embodiment, the fourth key may be K. AUSF .
[0160] In some embodiments, after generating the first key, the second node may store the first key in the first authentication vector. In one embodiment, the second node may replace the fourth key in the first authentication vector with the first key.
[0161] In some embodiments, after receiving a terminal authentication information acquisition response message containing a first authentication vector, the second node may store a third authentication response value and generate a fifth authentication response value based on the third authentication response value. In one embodiment, the fifth authentication response value may be HXRES*.
[0162] In some embodiments, after generating the fifth authentication response value, the second node may store the fifth authentication response value in the first authentication vector. In one embodiment, the second node may replace the third authentication response value in the first authentication vector with the fifth authentication response value.
[0163] In some embodiments, after the second node generates the first key, the second node may send a fourth message to the first node. This fourth message may be a response to a terminal authentication request message, and may include a first authentication vector.
[0164] In some embodiments, the fourth message can be used to trigger the first node to send a seventh message to the terminal. The seventh message is used to request the terminal to authenticate with the network. In one embodiment, when the second node performs initial authentication of the terminal using the AKA method, the second node sends a fourth message to the first node to trigger the first node to send the seventh message to the terminal, thereby enabling the terminal to authenticate with the network.
[0165] In some embodiments, after receiving a terminal authentication information acquisition response message containing a second authentication vector, the second node may send a terminal authentication response message to the first node.
[0166] In one embodiment, when the second authentication vector is generated based on the EAP-AKA′ method, the terminal authentication response message may include an EAP-Request / AKA′-Challenge message. In some embodiments, the EAP-Request / AKA′-Challenge message may be determined based on the response message obtained from the terminal authentication information, and the EAP-Request / AKA′-Challenge message may include a second random number and an authentication token.
[0167] In some embodiments, after receiving the terminal authentication response message, the first node may send a fifth message to the terminal. In one embodiment, the fifth message may include an EAP request / AKA' challenge message.
[0168] In some embodiments, the fifth message may further include third information, wherein the third information is used to identify a security context derived based on the first key. In some embodiments, the third information may be a key set identifier (ngKSI). In one embodiment, after receiving the first key, the first node may create the third information based on the first key.
[0169] In some embodiments, the fifth message may be an authentication request message, used to request the terminal to authenticate the network.
[0170] In some embodiments, after receiving the fifth message, the terminal can verify the authentication token based on the second random number. In one embodiment, the terminal can verify the authentication token based on the second random number and its own root key.
[0171] In some embodiments, if authentication token verification fails, the terminal can determine that authentication for the network has failed, and the authentication process ends.
[0172] In some embodiments, if the authentication token is successfully verified, the terminal can determine that the authentication for the network has been successful.
[0173] In some embodiments, upon successful authentication token verification, the terminal may generate a second authentication response value based on a second random number. In one embodiment, the terminal may generate the second authentication response value based on the second random number and its own root key. In one embodiment, the second authentication response value may be RES.
[0174] In some embodiments, after the terminal generates the first authentication response value, the terminal sends a sixth message to the first node. The sixth message may include an EAP response / AKA' challenge message.
[0175] In some embodiments, the EAP response / AKA' challenge message may include a second authentication response value.
[0176] In some embodiments, after receiving the sixth message, the first node may send a terminal authentication request message to the second node. The terminal authentication request message is used to request authentication of the terminal.
[0177] In some embodiments, the terminal authentication request message may include an EAP response / AKA' challenge message.
[0178] In some embodiments, after receiving the sixth message, the first node can further encapsulate the EAP response / AKA' challenge message in the sixth message into a terminal authentication request message to transmit the EAP response / AKA' challenge message to the second node.
[0179] In some embodiments, after receiving a terminal authentication request message, the second node authenticates the terminal based on a second authentication response value. In one embodiment, after receiving the terminal authentication request message, the second node can obtain the second authentication response value based on the EAP response / AKA' challenge message in the terminal authentication request message, and determine the authentication result for the terminal based on the second authentication response value and a locally stored fourth authentication response value. If the second authentication response value and the fourth authentication response value are different, the terminal authentication is determined to have failed, and the authentication process ends. If the second authentication response value and the fourth authentication response value are the same, the terminal is determined to have passed authentication.
[0180] In some embodiments, if the terminal is authenticated, the second node may send a fourth message to the first node. This fourth message may include the first key.
[0181] In some embodiments, the fourth message may be a message sent by the second node upon successful authentication of the terminal.
[0182] In some embodiments, the fourth message may further include a sixth message, which indicates that the second node has successfully authenticated the terminal. In one embodiment, the sixth message may be an EAP success message.
[0183] In one embodiment, when the second node performs the first authentication of the terminal using the EAP-AKA' algorithm, the second node sends a fourth message to the first node to indicate that the first authentication of the terminal was successful.
[0184] Step S2102: The first node determines the first security algorithm.
[0185] In some embodiments, the first node determines a first security algorithm based on first information and second information. The first information indicates the security algorithms supported by the terminal, and the second information indicates the security algorithms supported by the first node. In one example, the security algorithm may include at least one of an integrity algorithm, a confidentiality algorithm, etc.
[0186] In some embodiments, the first node may determine a first security algorithm according to a protocol agreement. In one embodiment, the security algorithm for communication protection between the first node and the terminal may be pre-agreed upon by the protocol. The first node and the terminal may determine the first security algorithm according to the protocol agreement.
[0187] In some embodiments, the first node can determine the first security algorithm based on the indication information sent by the second node. In one embodiment, during the initial authentication of the terminal by the second node, the second node can learn about the security algorithms supported by the terminal and the security algorithms supported by the first node. Therefore, the second node can select the first security algorithm for the terminal and the first node based on the security algorithms supported by the terminal and the first node, and the second node can use the indication information to inform the first node of the selected first security algorithm.
[0188] In some embodiments, the first information may be first capability information, which is used to indicate the security capabilities of the terminal. In one embodiment, during the initial authentication of the terminal, the first node learns the security capabilities of the terminal based on the first information sent by the second node or the first information sent by the terminal itself.
[0189] In some embodiments, the second information may be second capability information, which is used to indicate the security capabilities of the first node.
[0190] In some embodiments, the first security algorithm is a security algorithm negotiated between the first node and the terminal. In one embodiment, the first node can determine the first security algorithm based on the terminal's security capabilities and its own security capabilities.
[0191] In some embodiments, the first security algorithm can be used by the first node to generate the second key.
[0192] Step S2103: The first node generates a second key based on the first key and the first security algorithm.
[0193] In some embodiments, the first node may generate a second key based on at least one of the first key and information related to the first security algorithm, such as algorithm identifier, length of algorithm identifier, algorithm type of the first security algorithm, and length of algorithm type.
[0194] In some embodiments, the first node may use the first key as the input key to the Key Derivation Function (KDF), and at least one of the following: information related to the first security algorithm, such as the algorithm identifier, the length of the algorithm identifier, and the length of the algorithm type of the first security algorithm, as the generation parameter for the second key. The first node inputs the input key and the generation parameter together into the KDF to generate the second key.
[0195] In some embodiments, the algorithm identifier of the first security algorithm can be used to uniquely identify the first security algorithm.
[0196] In some embodiments, the algorithm type of the first security algorithm can be used to indicate the type of the first security algorithm. For example, the algorithm type of the first security algorithm may include at least one of the following: confidentiality algorithm; integrity algorithm.
[0197] In some embodiments, the first node can generate a first key based on a first key and the algorithm identifier of a first security algorithm. In some embodiments, the first node can generate a second key based on the first key, the algorithm identifier of the first security algorithm, and the length of the algorithm identifier. In some embodiments, the first node can generate a second key based on the first key, the algorithm identifier of the first security algorithm, and the algorithm type of the first security algorithm. In some embodiments, the first node can generate a second key based on the first key, the algorithm identifier of the first security algorithm and the length of the algorithm identifier, as well as the algorithm type of the first security algorithm and the length of the algorithm type.
[0198] In one example, the first node uses KDF, taking the first key as input and combining it with one or more of the following parameters to generate the second key: P0 = algorithm type distinguisher, L0 = length of P0; P1 = security algorithm identifier; L1 = length of P1.
[0199] For example, the type of the first security algorithm includes, but is not limited to, at least one of the following: integrity algorithm; confidentiality algorithm.
[0200] For example, the security algorithm identifier can be the identifier of Advanced Encryption Standard (AES), the identifier of Zu Chongzhi Algorithm (ZUC), etc.
[0201] In some embodiments, the second key includes at least one of the following: a confidentiality key and an integrity key.
[0202] In some embodiments, the confidentiality key can be used for confidentiality protection. In one embodiment, the confidentiality key can be used to encrypt plaintext data transmitted between the terminal and the first node to obtain corresponding ciphertext, preventing malicious entities from eavesdropping on the plaintext data transmitted between the terminal and the first node, thereby protecting the security of the plaintext data.
[0203] In some embodiments, the integrity key can be used for integrity protection. In one embodiment, the integrity key can be used to generate corresponding verification codes based on the data transmitted between the terminal and the first node, preventing malicious entities from tampering with the data transmitted between the terminal and the first node, thereby protecting the integrity of the data.
[0204] In some embodiments, when the algorithm type of the first security algorithm is a confidentiality algorithm, the first node generates a confidentiality key (such as a second key) based on the first key and the first security algorithm.
[0205] In some embodiments, when the algorithm type of the first security algorithm is an integrity algorithm, the first node generates an integrity key (such as a second key) based on the first key and the first security algorithm.
[0206] Step S2104: The first node sends the first message to the terminal.
[0207] In some embodiments, the terminal receives a first message sent by the first node.
[0208] In some embodiments, the first message may be sent by the first node, or by other network elements and / or access network devices.
[0209] In one example, the first node may send a first message to the AMF and / or access network device, and the AMF and / or access network device may forward the first message to the terminal.
[0210] In some embodiments, the first message is used to trigger the terminal to generate a second key.
[0211] In some embodiments, the first message is further used by the terminal to determine a first security algorithm, which is used by the terminal to generate a second key. In one embodiment, the first message may be a NAS Security Mode Command (SMC) message.
[0212] In some embodiments, the first security algorithm is also used by the first node to determine the algorithm employed when protecting communication based on the second key. In one embodiment, the first security algorithm is required when the first node uses the second key to protect the communication content between the first node and the terminal.
[0213] In one example, when the first node uses the second key to protect the integrity of the communication content between the first node and the terminal, an integrity algorithm is required. In another example, when the first node uses the second key to protect the confidentiality of the communication content between the first node and the terminal, a confidentiality algorithm is required.
[0214] In some embodiments, the first message is a message whose integrity is protected by the first node using the second key.
[0215] In some embodiments, the first message may include at least one of the following: third information for identifying a first key; fourth information for identifying a first security algorithm; and fifth information for identifying a first verification value.
[0216] In some embodiments, the third information may be a key set identifier.
[0217] In some embodiments, the third information may also be used to identify the first security context. The first security context is a security context derived by the first node based on the first key, and the first security context may be a NAS security context between the first node and the terminal.
[0218] In some embodiments, the fourth information can be used by the terminal to determine the first security algorithm.
[0219] In some embodiments, the fourth information may be the algorithm identifier of the first security algorithm.
[0220] In some embodiments, the first verification value is a message verification value obtained by the first node using a second key to perform integrity protection on the first message. In one embodiment, the first verification value may be a Message Authentication Code (MAC) value.
[0221] In some embodiments, the first verification value can be used by the terminal to verify the integrity of the first message.
[0222] In some embodiments, the first message may further include first information, which is further used by the terminal to determine whether the security algorithm supported by the terminal and sent to the first node has been tampered with. In one embodiment, the first node may send a first message containing the first information to the terminal. After receiving the first message, the terminal can determine whether the security algorithm supported by the terminal and sent to the first node before the establishment of secure communication has been tampered with, based on the stored security algorithms it supports and the security algorithm indicated by the first information in the first message.
[0223] In some embodiments, the first message may further include sixth information, which indicates that the second node has successfully authenticated the terminal. In one embodiment, the sixth information may be EAP success information. If the authentication algorithm used for the terminal's initial authentication is the EAP-AKA' algorithm, the first message may include EAP success information.
[0224] In some embodiments, the first message may further include seventh information, which is used to request the terminal to authenticate with the network. In one embodiment, the seventh information may be authentication request information. If the authentication algorithm used for the terminal's initial authentication is the AKA algorithm, the first message may include authentication request information.
[0225] In some embodiments, the seventh piece of information may include a first random number (RAND) and an authentication token (AUTN). In one embodiment, the first random number and the authentication token are used in an endpoint authentication service network.
[0226] In some embodiments, the first message may further include: ninth information, which is used to request the complete message content of the initial NAS message. In one embodiment, if the terminal successfully verifies the integrity of the first message after receiving the first message containing the ninth information, the terminal may send a second message containing the complete message content of the initial NAS message to the first node.
[0227] Step S2105: The terminal determines the first security algorithm based on the first message.
[0228] In some embodiments, when the first message includes fourth information, the terminal can determine the first security algorithm based on the fourth information. In one embodiment, since the first node and the terminal may support multiple different security algorithms and algorithm priorities respectively, after the first node selects a first security algorithm that it and the terminal both prioritize based on its own security capabilities and the terminal's security capabilities, it can inform the terminal of the selected first security algorithm through the fourth information, so that the first node and the terminal can complete the negotiation of the security algorithm.
[0229] In some embodiments, the first security algorithm is a security algorithm negotiated between the terminal and the first node.
[0230] In some embodiments, the first security algorithm can be used by the terminal to generate a second key.
[0231] In some embodiments, the first security algorithm is further used by the terminal to determine the algorithm employed when protecting communication based on the second key. In one embodiment, the first security algorithm is required when the terminal uses the second key to protect the communication content between the first node and the terminal.
[0232] In one example, when the terminal uses a second key to protect the integrity of the communication content between the first node and the terminal, an integrity algorithm is required. In another example, when the terminal uses a second key to protect the confidentiality of the communication content between the first node and the terminal, a confidentiality algorithm is required.
[0233] Step S2106: The terminal generates a second key based on the first key and the first security algorithm.
[0234] In some embodiments, the terminal may generate a second key based on the first key and information related to the first security algorithm, such as at least one of the following: algorithm identifier, length of algorithm identifier, algorithm type of the first security algorithm, and length of algorithm type.
[0235] In some embodiments, the terminal may use a first key as the input key to the KDF, and at least one of the following as generation parameters for the second key: the algorithm identifier of the first security algorithm, the length of the algorithm identifier, the algorithm type of the first security algorithm, and the length of the algorithm type. The terminal inputs the input key and the generation parameters together into the KDF to generate the second key.
[0236] In some embodiments, the terminal can generate a second key based on a first key and the algorithm identifier of a first security algorithm. In some embodiments, the terminal can generate a second key based on the first key, the algorithm identifier of the first security algorithm, and the length of the algorithm identifier. In some embodiments, the terminal can generate a second key based on the first key, the algorithm identifier of the first security algorithm, and the algorithm type of the first security algorithm. In some embodiments, the terminal can generate a second key based on the first key, the algorithm identifier of the first security algorithm, the length of the algorithm identifier, the algorithm type of the first security algorithm, and the length of the algorithm type.
[0237] In one example, the terminal uses KDF, taking the first key as input and combining it with one or more of the following parameters to generate the second key: P0 = algorithm type distinguisher, L0 = length of P0; P1 = security algorithm identifier; L1 = length of P1.
[0238] In some embodiments, the second key includes at least one of the following: a confidentiality key and an integrity key.
[0239] In some embodiments, when the algorithm type of the first security algorithm is a confidentiality algorithm, the terminal generates a confidentiality key based on the first key and the first security algorithm.
[0240] In some embodiments, when the algorithm type of the first security algorithm is an integrity algorithm, the terminal generates an integrity key based on the first key and the first security algorithm.
[0241] In some embodiments, the first key is a shared key generated by the terminal during initial authentication. In one embodiment, the first key may be K. SEAF .
[0242] In some embodiments, the terminal can generate a fourth key and generate a first key based on the fourth key, wherein the fourth key is a key between the terminal and the second node. In one embodiment, the fourth key may be K. AUSF .
[0243] In some embodiments, the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal. In one embodiment, since the first key is shared between the terminal and the first node during the initial authentication of the terminal, once the terminal receives the first message sent by the first node, the terminal can generate the second key based on the first key and the first security algorithm, so that the terminal can use the second key to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
[0244] In one embodiment, the second key generated by the terminal and the second key generated by the first node can be symmetric keys. In another embodiment, the second key generated by the terminal and the second key generated by the first node can also be asymmetric keys.
[0245] In this embodiment of the disclosure, the process of the terminal generating the second key in step S2106 is similar to the process of the first node generating the second key in step S2103. The first node in step S2103 can be replaced by the terminal. Accordingly, the process of the terminal generating the second key can refer to the process of the first node generating the second key in step S2103, and will not be described in detail here.
[0246] Step S2107: The terminal uses the second key to verify the integrity of the first message.
[0247] In some embodiments, since the first message is a message whose integrity is protected by the first node using the second key, the terminal can use the second key to verify the integrity of the first message after generating the second key, so as to determine whether the first message has been tampered with based on the integrity verification result of the first message.
[0248] In some embodiments, when the first message includes fifth information, the terminal determines a second verification value, and based on the second verification value and the first verification value, determines the integrity verification result of the first message.
[0249] In some embodiments, the second verification value is a message verification value obtained by the terminal using a second key to protect the integrity of the first message. In one embodiment, after determining the second verification value, the terminal can determine the integrity verification result of the first message by determining whether the second verification value is the same as the first verification value indicated by the fifth information. If the second verification value and the first verification value are the same, the terminal can determine that the integrity verification of the first message is successful. If the second verification value and the first verification value are different, the terminal can determine that the integrity verification of the first message fails.
[0250] In some embodiments, if the integrity verification of the first message is successful, the terminal can determine that the initial authentication of the terminal is successful. In one embodiment, when the authentication method used for the initial authentication of the terminal is the EAP-AKA' method, if the integrity verification of the first message is successful, the terminal can determine that the initial authentication of the terminal is successful.
[0251] In some embodiments, if the first message includes seventh information, and the integrity verification of the first message is successful, the terminal performs verification with the network based on the seventh information. In one embodiment, if the authentication method used for the initial authentication of the terminal is the AKA method, and the integrity verification of the first message is successful, the terminal performs verification with the network.
[0252] In some embodiments, the terminal may verify the authentication token based on a first random number. In one embodiment, the terminal may verify the authentication token based on the first random number and its own root key.
[0253] In some embodiments, if the authentication token verification fails, the terminal can determine that the authentication has failed and the authentication process ends.
[0254] In some embodiments, if the authentication token is successfully verified, the terminal can determine that the authentication was successful.
[0255] In some embodiments, if the authentication token is successfully verified, the terminal may generate a first authentication response value based on a first random number.
[0256] In some embodiments, the first authentication response value is used by the network to authenticate the terminal. In one embodiment, the first authentication response value may be RES*.
[0257] In one embodiment, the terminal can generate a second authentication response value based on a first random number and its own root key; and generate a first authentication response value based on the second authentication response value. In one embodiment, the second authentication response value may be RES.
[0258] In some embodiments, if the integrity verification of the first message is successful, the terminal sends a second message to the first node. This second message is protected by the terminal using a second key. It is worth noting that from this step onwards, messages between the terminal and the first node are protected by the second key.
[0259] In some embodiments, the second message may be a response message to the first message.
[0260] In some embodiments, the second message may be used to instruct the terminal and the first node to complete the negotiation of the first security algorithm.
[0261] In some embodiments, the second message may be an SMC completion message.
[0262] In some embodiments, where the first message includes seventh information, the second message may include eighth information, which indicates the first authentication response value. In one embodiment, where the authentication algorithm used for the initial authentication of the terminal is the AKA method, the terminal may send a second message containing the eighth message to the first node after successful authentication token verification, so that the first node can authenticate the terminal.
[0263] In some embodiments, the eighth information may be response information of the seventh information. In one embodiment, the eighth information may be authentication response information.
[0264] In some embodiments, where the first message includes the ninth information, the second message may also include the entire message content of the initial NAS message.
[0265] In some embodiments, the initial NAS message may be a NAS message that the terminal needs to send to the first node.
[0266] In some embodiments, after receiving the second message, the first node can use the second key to decode and verify the second message.
[0267] In some embodiments, where the second message includes an eighth message, the first node may authenticate the terminal based on the first authentication response value.
[0268] In some embodiments, the first node may generate a sixth authentication response value based on the first authentication response value, and determine the authentication result for the terminal based on the sixth authentication response value and the stored fifth authentication response value. If the sixth authentication response value and the fifth authentication response value are different, the terminal authentication is determined to have failed, and the authentication process ends. If the sixth authentication response value and the fifth authentication response value are the same, the terminal authentication is determined to have passed. Here, if the terminal passes authentication, it may be considered as having passed authentication from the perspective of the serving network.
[0269] In one embodiment, the sixth authentication response value may be HRES*, and the fifth authentication response value may be HXRES*.
[0270] In some embodiments, after the first node determines that the terminal has passed authentication, the first node may send tenth information to the second node, which is used to request the second node to authenticate the terminal. The tenth information may include a first authentication response value.
[0271] In some embodiments, after receiving the tenth information, the second node can authenticate the terminal based on the first authentication response value.
[0272] In some embodiments, the second node can determine the authentication result for the terminal based on the stored third authentication response value and the first authentication response value. If the third authentication response value and the first authentication response value are different, the terminal authentication is determined to have failed, and the authentication process ends. If the third authentication response value and the first authentication response value are the same, the terminal authentication is determined to have passed. Here, if the terminal passes authentication, it can be considered to have passed authentication from the perspective of the home network.
[0273] In one embodiment, if the terminal passes authentication, the second node can determine that the first authentication for the terminal was successful.
[0274] In some embodiments, after the second node determines that the terminal has passed authentication, the second node sends an eleventh message to the first node, which is used to indicate that the terminal has passed authentication.
[0275] In some embodiments, if the integrity verification of the first message fails, the terminal may determine that the first message has been tampered with and discard the first message.
[0276] In some embodiments, if the integrity verification of the first message fails, the terminal may send a third message to the first node. The third message is an unprotected message.
[0277] In some embodiments, the third message may be a response message to the first message.
[0278] In some embodiments, the third message may be an SMC rejection message.
[0279] In some embodiments, the third message can be used to trigger the first node to resend the first message to the terminal.
[0280] In some embodiments, after receiving the third message, the first node can resend the first message to the terminal.
[0281] In some embodiments, the third message may include a twelfth message, which is used to request the first node to resend the first message.
[0282] In some embodiments, after receiving a third message containing twelfth information, the first node may resend the first message to the terminal.
[0283] In some embodiments, if the integrity verification of the first message resent by the first node fails, the terminal may send a third message to the first node.
[0284] In some embodiments, if the first node receives a third message after resending the first message, it can determine that the terminal's initial authentication has failed and stop the authentication process.
[0285] In some embodiments, if the integrity verification of the first message resent by the first node fails, the terminal may send a third message to the first node that does not contain the twelfth message.
[0286] In some embodiments, if the first node receives a third message that does not contain the twelfth message, it can determine that the terminal's initial authentication has failed and stop the authentication process.
[0287] In some embodiments, the term "information" may be used interchangeably with terms such as "message," "signal," "signaling," "report," "configuration," "indication," "instruction," "command," "channel," "parameter," "field," and "data."
[0288] In some embodiments, the term "send" may be used interchangeably with terms such as "transmit," "report," or "transmit."
[0289] Figure 2B is a schematic diagram of an interactive data security processing method according to an exemplary embodiment. As shown in Figure 2B, this disclosure relates to a data security processing method for a communication system 100, the method comprising:
[0290] Step S2201: The second node sends the fourth message to the first node.
[0291] In some embodiments, the first node receives a fourth message sent by the second node.
[0292] In some embodiments, other optional implementations of step S2201 can be found in the optional implementations of step S2101 in FIG2A and other related parts in the embodiments involved in FIG2A, which will not be repeated here.
[0293] Step S2202: The first node generates a third key based on the first key.
[0294] In some embodiments, the first node may generate a third key based on the first key and the third information.
[0295] In some embodiments, the first node can use the first key as the input key of the KDF and the third information as the generation parameter of the third key. The first node inputs the input key and the generation parameter into the KDF together to generate the third key.
[0296] In some embodiments, the third information is used to identify the security context derived based on the first key. In some embodiments, the third information may be a key set identifier ngKSI.
[0297] In one embodiment, the first node can generate a third key based on the first key and ngKSI. In another embodiment, the first node can generate the third key based on the first key, ngKSI, and the length of ngKSI.
[0298] In one example, the first node uses KDF, taking the first key as input and combining it with one or more of the following parameters to generate the third key: P0 = ngKSI, L0 = the length of P0.
[0299] In some embodiments, the third key is used by the first node to generate the second key.
[0300] Step S2203: The first node determines the first security algorithm.
[0301] In some embodiments, other optional implementations of step S2203 can be found in the optional implementations of step S2102 in FIG2A and other related parts in the embodiments involved in FIG2A, which will not be repeated here.
[0302] Step S2204: The first node generates a second key based on the third key and the first security algorithm.
[0303] In some embodiments, the first node may generate a second key based on at least one of the third key and information related to the first security algorithm, such as the algorithm identifier, the length of the algorithm identifier, the algorithm type of the first security algorithm, and the length of the algorithm type.
[0304] In some embodiments, the first node may use a third key as the input key to the KDF, and at least one of the following: information related to the first security algorithm, such as the algorithm identifier, the length of the algorithm identifier, and the length of the algorithm type of the first security algorithm, as the generation parameter for the second key. The first node inputs the input key and the generation parameter together into the KDF to generate the second key.
[0305] In some embodiments, the algorithm identifier of the first security algorithm can be used to uniquely identify the first security algorithm.
[0306] In some embodiments, the algorithm type of the first security algorithm can be used to indicate the type of the first security algorithm. For example, the algorithm type of the first security algorithm may include at least one of the following: confidentiality algorithm; integrity algorithm.
[0307] In some embodiments, the first node can generate a third key based on a third key and the algorithm identifier of a first security algorithm. In some embodiments, the first node can generate a second key based on the third key, the algorithm identifier of the first security algorithm, and the length of the algorithm identifier. In some embodiments, the first node can generate a second key based on the third key, the algorithm identifier of the first security algorithm, and the algorithm type of the first security algorithm. In some embodiments, the first node can generate a second key based on the third key, the algorithm identifier of the first security algorithm and the length of the algorithm identifier, as well as the algorithm type of the first security algorithm and the length of the algorithm type.
[0308] In one example, the first node uses KDF, takes the third key as input, and generates the second key by combining one or more of the following parameters: P0 = algorithm type distinguisher, L0 = length of P0; P1 = security algorithm identifier; L1 = length of P1.
[0309] For example, the type of the first security algorithm includes, but is not limited to, one of the following: integrity algorithm and / or confidentiality algorithm.
[0310] For example, the security algorithm identifier can be the identifier for Advanced Encryption Standard (AES), the identifier for Zu Chongzhi Algorithm (ZUC), etc.
[0311] In some embodiments, the second key includes at least one of the following: a confidentiality key and an integrity key.
[0312] In some embodiments, the confidentiality key can be used for confidentiality protection. In one embodiment, the confidentiality key can be used to encrypt plaintext data transmitted between the terminal and the first node to obtain corresponding ciphertext, preventing malicious entities from eavesdropping on the plaintext data transmitted between the terminal and the first node, thereby protecting the security of the plaintext data.
[0313] In some embodiments, the integrity key can be used for integrity protection. In one embodiment, the integrity key can be used to generate corresponding verification codes based on the data transmitted between the terminal and the first node, preventing malicious entities from tampering with the data transmitted between the terminal and the first node, thereby protecting the integrity of the data.
[0314] In some embodiments, when the algorithm type of the first security algorithm is a confidentiality algorithm, the first node generates a confidentiality key (such as a second key) based on the third key and the first security algorithm.
[0315] In some embodiments, when the algorithm type of the first security algorithm is an integrity algorithm, the first node generates an integrity key (such as a second key) based on the third key and the first security algorithm.
[0316] Step S2205: The first node sends the first message to the terminal.
[0317] In some embodiments, the terminal receives a first message sent by the first node.
[0318] In some embodiments, the first message may be sent by the first node, or by other network elements and / or access network devices.
[0319] In one example, the first node may send a first message to the AMF and / or access network device, and the AMF and / or access network device may forward the first message to the terminal.
[0320] In some embodiments, other optional implementations of step S2205 can be found in the optional implementations of step S2104 in FIG2A and other related parts in the embodiments involved in FIG2A, which will not be repeated here.
[0321] Step S2206: The terminal determines the first security algorithm based on the first message.
[0322] In some embodiments, other optional implementations of step S2206 can be found in the optional implementations of step S2105 in FIG2A and other related parts in the embodiments involved in FIG2A, which will not be repeated here.
[0323] Step S2207: The terminal generates a third key based on the first key.
[0324] In some embodiments, the terminal may generate a third key based on the first key and the third information.
[0325] In some embodiments, the terminal can use the first key as the input key of the KDF and the third information as the generation parameter of the third key. The terminal inputs the input key and the generation parameter together into the KDF to generate the third key.
[0326] In one example, the terminal uses KDF, taking the first key as input and combining it with one or more of the following parameters to generate a third key: P0 = ngKSI, L0 = the length of P0.
[0327] In some embodiments, the third key is used by the terminal to generate the second key.
[0328] In this embodiment of the disclosure, the process of the terminal generating the third key in step S2207 is similar to the process of the first node generating the second key in step S2202. The first node in step S2202 can be replaced by the terminal. Accordingly, the process of the terminal generating the second key can refer to the process of the first node generating the third key in step S2202, and will not be described in detail here.
[0329] Step S2208: The terminal generates a second key based on the third key and the first security algorithm.
[0330] In some embodiments, the terminal may generate a second key based on a third key and information related to the first security algorithm, such as at least one of the following: algorithm identifier, length of the algorithm identifier, algorithm type of the first security algorithm, and length of the algorithm type.
[0331] In some embodiments, the terminal may use a third key as the input key to the KDF, and at least one of the following as generation parameters for the second key: the algorithm identifier of the first security algorithm, the length of the algorithm identifier, the algorithm type of the first security algorithm, and the length of the algorithm type. The terminal inputs the input key and the generation parameters together into the KDF to generate the second key.
[0332] In some embodiments, the terminal can generate a second key based on a third key and the algorithm identifier of a first security algorithm. In some embodiments, the terminal can generate a second key based on the third key, the algorithm identifier of the first security algorithm, and the length of the algorithm identifier. In some embodiments, the terminal can generate a second key based on the third key, the algorithm identifier of the first security algorithm, and the algorithm type of the first security algorithm. In some embodiments, the terminal can generate a second key based on the third key, the algorithm identifier of the first security algorithm and the length of the algorithm identifier, as well as the algorithm type of the first security algorithm and the length of the algorithm type.
[0333] In one example, the terminal uses KDF, taking a third key as input, and combining it with one or more of the following parameters to generate a second key: P0 = algorithm type distinguisher, L0 = length of P0; P1 = security algorithm identifier; L1 = length of P1.
[0334] In some embodiments, the second key includes at least one of the following: a confidentiality key and an integrity key.
[0335] In some embodiments, when the algorithm type of the first security algorithm is a confidentiality algorithm, the terminal generates a confidentiality key based on the third key and the first security algorithm.
[0336] In some embodiments, when the algorithm type of the first security algorithm is an integrity algorithm, the terminal generates an integrity key based on the third key and the first security algorithm.
[0337] In some embodiments, the third key is a shared key generated by the terminal during initial authentication. In one embodiment, the third key may be K. SEAF .
[0338] In some embodiments, the terminal can generate a fourth key and generate a third key based on the fourth key, wherein the fourth key is a key between the terminal and the second node. In one embodiment, the fourth key may be K. AUSF .
[0339] In some embodiments, the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal. In one embodiment, since the terminal and the first node share a third key during the initial authentication of the terminal, once the terminal receives the first message sent by the first node, the terminal can generate a second key based on the third key and the first security algorithm, so that the terminal can use the second key to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
[0340] In this embodiment of the disclosure, the process of the terminal generating the second key in step S2208 is similar to the process of the first node generating the second key in step S2204. The first node in step S2204 can be replaced by the terminal. Accordingly, the process of the terminal generating the second key can refer to the process of the first node generating the second key in step S2204, and will not be described in detail here.
[0341] Step S2209: The terminal uses the second key to verify the integrity of the first message.
[0342] In some embodiments, other optional implementations of step S2209 can be found in the optional implementations of step S2107 in FIG2A and other related parts in the embodiments involved in FIG2A, which will not be repeated here.
[0343] The data security processing method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2209. For example, step S2201 in combination with steps S2203, S2205 to S2206, and S2209 can be implemented as an independent embodiment, but is not limited thereto.
[0344] In some embodiments, steps S2202 and S2203 may be performed in a different order or simultaneously, and steps S2206 and S2207 may be performed in a different order or simultaneously.
[0345] In some embodiments, steps S2202 and S2204 are optional, and one or more of these steps may be omitted or substituted in different embodiments. It is understood that the first node can directly generate the second key based on the first key and the first security algorithm, without needing to generate a third key.
[0346] In some embodiments, steps S2207 and S2208 are optional, and one or more of these steps may be omitted or substituted in different embodiments. It is understood that the terminal can directly generate the second key based on the first key and the first security algorithm, without needing to generate a third key.
[0347] Figure 3 is an interactive schematic diagram of a data security processing method according to an exemplary embodiment. As shown in Figure 3, this disclosure relates to a data security processing method, which includes:
[0348] Step S3101: The first node generates a second key based at least on the first key.
[0349] In some embodiments, the first key may be provided by the second node.
[0350] In some embodiments, the first node may receive a fourth message sent by the second node, the fourth message including the first key.
[0351] In some embodiments, the first node generates a second key based on a first key and a first security algorithm. The first security algorithm is determined by the first node based on first information and second information; the first information indicates the security algorithms supported by the terminal; and the second information indicates the security algorithms supported by the first node.
[0352] In some embodiments, the first node generates a second key based on a third key and a first security algorithm; the third key is generated by the first node based on the first key.
[0353] In some embodiments, a third key is generated based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0354] In some embodiments, the first node can generate a second key based on a first key, a first security algorithm, and a terminal identifier. Thus, the second key generated by the first node is different for different terminals, improving the communication security isolation between the first node and different terminals.
[0355] In some embodiments, other optional implementations of step S3101 can be found in the optional implementations of step S2103 in FIG2A, step S2204 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0356] Step S3102: The first node sends the first message to the terminal.
[0357] In some embodiments, the terminal receives a first message sent by the first node.
[0358] In some embodiments, the first message may be sent by the first node, or by other network elements and / or access network devices.
[0359] In one example, the first node may send a first message to the AMF and / or access network device, and the AMF and / or access network device may forward the first message to the terminal.
[0360] In some embodiments, the first message is used by the terminal to determine the first security algorithm, and the first security algorithm is used by the terminal to generate the second key and determine the algorithm used for communication protection.
[0361] In some embodiments, the first message is a message whose integrity is protected by the first node using the second key.
[0362] In some embodiments, the first message includes at least one of the following:
[0363] The third piece of information is used to identify the security context derived from the first key;
[0364] The fourth piece of information is used to identify the first security algorithm;
[0365] The fifth piece of information is used to indicate the first verification value; the first verification value is the message verification value obtained by the first node using the second key to protect the integrity of the first message, and the first verification value is used by the terminal to verify the integrity of the first message.
[0366] In some embodiments, the first message includes: first information for indicating the security algorithm supported by the terminal; the first information is also used by the terminal to determine whether the security algorithm supported by the terminal sent to the first node has been tampered with.
[0367] In some embodiments, the first message further includes one of the following:
[0368] The sixth piece of information is used to indicate that the second node has successfully authenticated the terminal's identity;
[0369] The seventh piece of information is used to request the terminal to authenticate with the network; the seventh piece of information includes: the first random number and the authentication token.
[0370] In some embodiments, other optional implementations of step S3102 can be found in the optional implementations of step S2104 in FIG2A, step S2205 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0371] Step S3103: The terminal generates a second key based at least on the first key.
[0372] In some embodiments, the terminal generates a second key based on a first key and a first security algorithm.
[0373] In some embodiments, the terminal generates a second key based on a third key and a first security algorithm.
[0374] In some embodiments, the terminal generates a third key based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0375] In some embodiments, the terminal can generate a second key based on a first key, a first security algorithm, and a terminal identifier. This ensures that different terminals generate different second keys than the first node, improving the communication security isolation between the first node and different terminals.
[0376] In some embodiments, the terminal determines a second verification value; based on the second verification value and the first verification value, it determines the integrity verification result of the first message. The first message includes fifth information, and the second verification value is a message verification value obtained by the terminal using a second key to protect the integrity of the first message.
[0377] In some embodiments, the terminal sends a second message to the first node; the second message is a message sent by the terminal after successfully verifying the integrity of the first message, and the second message is a message protected by the terminal using a second key.
[0378] In some embodiments, the second message includes: an eighth message, which is used to indicate a first authentication response value; the first authentication response value is used by the first node to authenticate the terminal; the first authentication response value is generated by the terminal based on a first random number after the authentication token is successfully verified.
[0379] In some embodiments, the terminal sends a third message to the first node; the third message is a message sent by the terminal after the integrity verification of the first message fails, and the third message is used to trigger the first node to resend the first message to the terminal.
[0380] In some embodiments, other optional implementations of step S3103 can be found in the optional implementations of step S2106 in FIG2A, step S2208 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0381] This disclosure also provides a data security processing method, which is executed by a communication system, and the method includes:
[0382] Step S3201: The second node sends the fourth message to the first node.
[0383] In some embodiments, the first node receives a fourth message sent by the second node.
[0384] In some embodiments, the fourth message may include a first key, which is used by the first node to generate a second key.
[0385] In some embodiments, the fourth message includes an authentication vector used by the terminal to authenticate itself with the network.
[0386] In some embodiments, the authentication vector includes a first key.
[0387] In some embodiments, other optional implementations of step S3201 can be found in step S2101 of FIG2A, optional implementations of step S2201 of FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0388] Step S3202: The first node generates a second key based at least on the first key.
[0389] In some embodiments, the first node generates a second key based on a first key and a first security algorithm. The first security algorithm is determined by the first node based on first information and second information; the first information indicates the security algorithms supported by the terminal; and the second information indicates the security algorithms supported by the first node.
[0390] In some embodiments, the first node generates a second key based on a third key and a first security algorithm; the third key is generated by the first node based on the first key.
[0391] In some embodiments, a third key is generated based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0392] In some embodiments, the first node can generate a second key based on a first key, a first security algorithm, and a terminal identifier. Thus, the second key generated by the first node is different for different terminals, improving the communication security isolation between the first node and different terminals.
[0393] In some embodiments, other optional implementations of step S3202 can be found in the optional implementations of step S2103 in FIG2A, step S2204 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0394] Step S3203: The first node sends the first message to the terminal.
[0395] In some embodiments, the terminal receives a first message sent by the first node.
[0396] In some embodiments, the first message may be sent by the first node, or by other network elements and / or access network devices.
[0397] In one example, the first node may send a first message to the AMF and / or access network device, and the AMF and / or access network device may forward the first message to the terminal.
[0398] In some embodiments, the first message is used by the terminal to determine the first security algorithm, and the first security algorithm is used by the terminal to generate the second key and determine the algorithm used for communication protection.
[0399] In some embodiments, the first message is a message whose integrity is protected by the first node using the second key.
[0400] In some embodiments, the first message includes at least one of the following:
[0401] The third piece of information is used to identify the security context derived from the first key;
[0402] The fourth piece of information is used to identify the first security algorithm;
[0403] The fifth piece of information is used to indicate the first verification value; the first verification value is the message verification value obtained by the first node using the second key to protect the integrity of the first message, and the first verification value is used by the terminal to verify the integrity of the first message.
[0404] In some embodiments, the first message includes: first information for indicating the security algorithm supported by the terminal; the first information is also used by the terminal to determine whether the security algorithm supported by the terminal sent to the first node has been tampered with.
[0405] In some embodiments, the first message further includes one of the following:
[0406] The sixth piece of information is used to indicate that the second node has successfully authenticated the terminal's identity;
[0407] The seventh piece of information is used to request the terminal to authenticate with the network; the seventh piece of information includes: the first random number and the authentication token.
[0408] In some embodiments, other optional implementations of step S3203 can be found in the optional implementations of step S2104 in FIG2A, step S2205 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0409] Step S3204: The terminal generates a second key based at least on the first key.
[0410] In some embodiments, the terminal generates a second key based on a first key and a first security algorithm.
[0411] In some embodiments, the terminal generates a second key based on a third key and a first security algorithm.
[0412] In some embodiments, the terminal generates a third key based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0413] In some embodiments, the terminal determines a second verification value; based on the second verification value and the first verification value, it determines the integrity verification result of the first message. The first message includes fifth information, and the second verification value is a message verification value obtained by the terminal using a second key to protect the integrity of the first message.
[0414] In some embodiments, the terminal sends a second message to the first node; the second message is a message sent by the terminal after successfully verifying the integrity of the first message, and the second message is a message protected by the terminal using a second key.
[0415] In some embodiments, the second message includes: an eighth message, which is used to indicate a first authentication response value; the first authentication response value is used by the first node to authenticate the terminal; the first authentication response value is generated by the terminal based on a first random number after the authentication token is successfully verified.
[0416] In some embodiments, the terminal sends a third message to the first node; the third message is a message sent by the terminal after the integrity verification of the first message fails, and the third message is used to trigger the first node to resend the first message to the terminal.
[0417] In some embodiments, the terminal can generate a second key based on a first key, a first security algorithm, and a terminal identifier. This ensures that different terminals generate different second keys than the first node, improving the communication security isolation between the first node and different terminals.
[0418] In some embodiments, other optional implementations of step S3204 can be found in the optional implementations of step S2106 in FIG2A, step S2208 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0419] This disclosure also provides a data security processing method, the method comprising:
[0420] Step S3301: The first node generates a second key based on at least the first key.
[0421] In some embodiments, the first key may be provided by the second node.
[0422] In some embodiments, the first node may receive a fourth message sent by the second node, the fourth message including the first key.
[0423] In some embodiments, the first node generates a second key based on a first key and a first security algorithm. The first security algorithm is determined by the first node based on first information and second information; the first information indicates the security algorithms supported by the terminal; and the second information indicates the security algorithms supported by the first node.
[0424] In some embodiments, the first node generates a second key based on a third key and a first security algorithm; the third key is generated by the first node based on the first key.
[0425] In some embodiments, a third key is generated based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0426] In some embodiments, the first node can generate a second key based on a first key, a first security algorithm, and a terminal identifier. Thus, the second key generated by the first node is different for different terminals, improving the communication security isolation between the first node and different terminals.
[0427] In some embodiments, the first node determines a first security algorithm based on first information and second information. The first information indicates the security algorithms supported by the terminal, and the second information indicates the security algorithms supported by the first node.
[0428] In some embodiments, the first information may be first capability information, which is used to indicate the security capabilities of the terminal. In one embodiment, during the initial authentication of the terminal, the first node learns the security capabilities of the terminal based on the first information sent by the second node or the first information sent by the terminal itself.
[0429] In some embodiments, the second information may be second capability information, which is used to indicate the security capabilities of the first node.
[0430] In some embodiments, the first node may determine a first security algorithm according to a protocol agreement. In one embodiment, the security algorithm for communication protection between the first node and the terminal may be pre-agreed upon in the protocol. The first node and the terminal may determine the first security algorithm according to the protocol agreement. If the first node needs to communicate with the terminal during the initial authentication process of the terminal, the first node may generate a second key based on the first security algorithm and the first key, so as to use the second key to protect the communication security between the terminal and the first node.
[0431] In some embodiments, the first node can determine the first security algorithm based on the indication information sent by the second node. In one embodiment, during the initial authentication of the terminal by the second node, the second node can learn about the security algorithms supported by the terminal and the security algorithms supported by the first node. Therefore, the second node can select the first security algorithm for the terminal and the first node based on the security algorithms supported by the terminal and the first node, and the second node can use the indication information to inform the first node of the selected first security algorithm.
[0432] In some embodiments, other optional implementations of step S3301 can be found in the optional implementations of step S2103 in FIG2A, step S2204 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0433] This disclosure also provides a data security processing method, the method comprising:
[0434] Step S3401: The terminal generates a second key based at least on the first key.
[0435] In some embodiments, the terminal generates a second key based on a first key and a first security algorithm.
[0436] In some embodiments, the terminal generates a second key based on a third key and a first security algorithm.
[0437] In some embodiments, the terminal generates a third key based on a first key and third information; the third information is used to identify a security context derived from the first key.
[0438] In some embodiments, the terminal can generate a second key based on a first key, a first security algorithm, and a terminal identifier. This ensures that different terminals generate different second keys than the first node, improving the communication security isolation between the first node and different terminals.
[0439] In some embodiments, the terminal may receive a first message sent by the first node and determine a first security algorithm based on the first message.
[0440] In some embodiments, the first message is a message whose integrity is protected by the first node using the second key.
[0441] In some embodiments, the first message includes at least one of the following:
[0442] The third piece of information is used to identify the security context derived from the first key;
[0443] The fourth piece of information is used to identify the first security algorithm;
[0444] The fifth piece of information is used to indicate the first verification value; the first verification value is the message verification value obtained by the first node using the second key to protect the integrity of the first message, and the first verification value is used by the terminal to verify the integrity of the first message.
[0445] In some embodiments, the first message includes: first information for indicating the security algorithm supported by the terminal; the first information is also used by the terminal to determine whether the security algorithm supported by the terminal sent to the first node has been tampered with.
[0446] In some embodiments, the first message further includes one of the following:
[0447] The sixth piece of information is used to indicate that the second node has successfully authenticated the terminal's identity;
[0448] The seventh piece of information is used to request the terminal to authenticate with the network; the seventh piece of information includes: the first random number and the authentication token.
[0449] In some embodiments, the terminal may determine a first security algorithm according to a protocol agreement. In one embodiment, the security algorithm for communication protection between the first node and the terminal may be pre-agreed upon in the protocol. When the first security algorithm is protocol-defined, if the terminal needs to communicate with the first node during its initial authentication process, the terminal may generate a second key based on the first security algorithm and the first key. This second key is then used to protect the communication security between the terminal and the first node, without requiring the first node to send a first message to the terminal.
[0450] In some embodiments, other optional implementations of step S3401 can be found in the optional implementations of step S2106 in FIG2A, step S2208 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.
[0451] To better understand the embodiments of this disclosure, the following exemplary embodiments will be used to further illustrate this disclosure.
[0452] In some embodiments, in a 5G system, messages between the terminal and the servicing network are protected by a NAS security mechanism and / or an Access Stratum (AS) security mechanism, which is established after the NAS security mechanism is established. This means that the basic security mechanism used for communication between the terminal and the servicing network is the NAS security mechanism, and the key for the NAS security mechanism is established by the SEAF and the UE based on the root key K after the terminal's initial successful authentication. AMF Yes, that's certain. Once the root key K is shared between the terminal and the service network... AMF This enables the establishment of security protection between the UE and the service network.
[0453] In some embodiments, a root key (i.e., K) is shared between the terminal and the service network. AMF The NAS security mechanism is exported after the initial successful authentication of the terminal, therefore it can only be established after the initial successful authentication of the terminal. However, K AMF This is not the only key shared between the terminal and the service network during the initial authentication process. AMF From K SEAF Exported from K SEAF It can be exported separately by the terminal and AUSF, and AUSF will export the K during the terminal's initial authentication. SEAF Send to SEAF so that K SEAF Shared between the terminal and SEAF. K SEAF The reasons why the root key was not used as the NAS security mechanism in 5G systems are as follows: 1) After the initial successful authentication of the terminal, there are no subsequent messages between the terminal and the SEAF, so there is no need to establish security protection between the terminal and the SEAF. After the initial successful authentication of the terminal, the AMF is a basic function in the serving network used for terminal access and mobility management. Establishing a NAS security mechanism between the terminal and the AMF is necessary to protect subsequent messages between the terminal and the serving network after the initial successful authentication of the terminal. 2) K SEAF Transmission outside of SEAF is not permitted; once SEAF is based on K... SEAF Export K AMF After that, K needs to be... SEAF Remove from SEAF.
[0454] However, in addition to the NAS connection between the terminal and the AMF, 6G networks can have a multi-NAS architecture. In a 6G multi-NAS architecture, K... SEAF It can be used as the root key to establish security for NAS connections between endpoints and multiple Network Functions (NFs). SEAF can be used as a security anchor function to establish security for NAS connections between endpoints and NFs. This means that subsequent communication between the endpoint and SEAF may be required after the initial authentication of the endpoint. For this purpose, K... SEAF It can be used as the root key for the NAS connection (i.e., NAS / SEAF connection) between the terminal and SEAF. This also means that in K AMF After being exported, K SEAF The root key K needs to be stored in SEAF for exporting NAS connections between the terminal and other NFs. NF .
[0455] In some embodiments, during the establishment and authentication protection of NAS / SEAF security, the initial authentication process of the terminal is the same as the existing process (i.e., the process shown in Figure 1B).
[0456] The terminal sends an N1 message, which includes the terminal identifier and terminal security capabilities. After the SEAF receives the N1 message from the terminal, according to the SEAF's policy, whenever the SEAF expects to initiate terminal authentication during the establishment of a signaling connection between the SEAF and the UE, the SEAF can send a terminal authentication request message (Nausf_UEAuthentication_Authenticate Request) to the AUSF to trigger the terminal authentication service. This terminal authentication request message may include the service network name. After receiving the terminal authentication request message, the AUSF can check whether the requesting SEAF in the service network indicated by the service network name has the right to use the terminal authentication service, and then the AUSF sends a terminal authentication information retrieval request message (Nudm_UEAuthentication_Get Request) to the Unified Data Management (UDM). After receiving the terminal authentication information retrieval request message, the UDM selects an authentication method from EAP-AKA′ and 6GAKA, and performs authentication based on the selected authentication method. As shown in Figure 4A, Figure 4A is a schematic diagram of an authentication process based on EAP-AKA′ according to an exemplary embodiment.
[0457] 1. When the UDM or Authentication Credentials Repository and Processing Function (ARPF) receives the Terminal Authentication Information Acquisition Request message sent by AUSF and initiates authentication of the terminal, the UDM or ARPF generates an Authentication Vector (AV) and sends a Terminal Authentication Information Acquisition Response message (Nudm_UEAuthentication_Get Response) to AUSF. This Terminal Authentication Information Acquisition Response message includes the AV and an indication that the AV will be used for EAP-AKA′.
[0458] 2. AUSF sends an endpoint authentication response message (Nausf_UEAuthentication_Authenticate Response) to SEAF, which includes an EAP request / AKA' challenge message.
[0459] 3. SEAF transparently forwards EAP request / AKA' challenge messages to the endpoint via authentication request messages. These authentication request messages can be NAS messages.
[0460] 4. The terminal verifies the freshness of the AV and calculates the response RES. Then, the terminal sends an Auth-Response message to SEAF. This NAS message includes an EAP-Response / AKA'-Challenge message containing the RES. The Auth-Response message can be a NAS message.
[0461] 5. SEAF transparently forwards the EAP response / AKA' challenge message to AUSF via the terminal authentication request message.
[0462] 6. AUSF verifies the EAP response / AKA' challenge message by comparing the expected response XRES with the received RES. If the EAP response / AKA' challenge message is successfully verified, AUSF derives K. AUSF And based on K AUSF Generate K SEAF Then, AUSF sends an Endpoint Authentication Response (EAS) message to SEAF to transparently forward the EAP Success information to the endpoint. The EAS message may include K... SEAF .
[0463] 7a. When SEAF receives K SEAF SEAF can select a matching security algorithm based on the terminal's security capabilities received during the initial authentication process and SEAF's own security capabilities, and then base its selection on the selected security algorithm and K. SEAF Export the NAS / SEAF security context. After establishing the NAS / SEAF security context, SEAF activates NAS / SEAF integrity protection before sending NAS / SEAF SMC messages.
[0464] 7b. SEAF sends a NAS / SEAF SMC message to the terminal. This NAS / SEAF SMC message may include the terminal's security capabilities for replay, the selected security algorithm, and the method used to identify K. SEAF ngKSI.
[0465] In some embodiments, the NAS / SEAF SMC message may also include a flag requesting a complete initial NAS message.
[0466] In some embodiments, the NAS / SEAF SMC message may also include EAP success information.
[0467] In some embodiments, the NAS / SEAF SMC message may include a Message Authentication Code (MAC) value for the NAS / SEAF SMC message. In one embodiment, SEAF may use a K value based on the ngKSI indication. SEAF The NAS / SEAF integrity key is used to perform integrity protection on NAS / SEAF SMC messages to obtain the MAC value of the NAS / SEAF SMC messages.
[0468] 8a. When the terminal receives a NAS / SEAF SMC message containing EAP success information and a MAC value, the terminal can export K in the same way as AUSF in step 6. AUSF And based on K AUSF Generate K SEAF Then the terminal verifies the NAS / SEAF SMC message.
[0469] In some embodiments, before verifying the NAS / SEAF SMC message, the terminal uses a selected security algorithm from K SEAF Export the NAS / SEAF security context indicated by ngKSI.
[0470] In some embodiments, the terminal's verification of NAS / SEAF SMC messages may include: verifying whether the terminal's stored terminal security capabilities match the terminal security capabilities sent by SEAF, and using the NAS / SEAF integrity key and NAS / SEAF integrity algorithm exported by the terminal to verify the integrity of the NAS / SEAF SMC messages.
[0471] In some embodiments, if the integrity verification of the NAS / SEAF SMC message is successful, the terminal may consider the first authentication successful and activate NAS / SEAF integrity protection and confidentiality protection using the NAS / SEAF security context indicated by ngKSI.
[0472] In some embodiments, if the integrity verification of the NAS / SEAF SMC message fails, the terminal may assume that the NAS / SEAF SMC message has been tampered with by an attacker and discard the received NAS / SEAF SMC message.
[0473] 8b. If the integrity verification of the NAS / SEAF SMC message is successful, the terminal sends a protected NAS / SEAF SMC completion message to SEAF.
[0474] In some embodiments, the NAS / SEAF SMC completion message is protected for integrity and confidentiality by the endpoint using the NAS / SEAF security context.
[0475] In some embodiments, if the NAS / SEAF SMC message includes a flag requesting a complete initial NAS message, the NAS / SEAF SMC completion message sent by the endpoint may include the complete initial NAS message. It is worth noting that from this step onwards, all messages between the endpoint and SEAF are protected by the NAS / SEAF security context.
[0476] In some embodiments, SEAF uses the NAS / SEAF security context indicated in the NAS / SEAF SMC message to decrypt and verify the integrity of the NAS / SEAF SMC completion message.
[0477] If the integrity verification of the NAS / SEAF SMC message fails, the endpoint can send a NAS / SEAF SMC rejection message to the SEAF. When the SEAF receives the NAS / SEAF SMC rejection message, it can re-initiate the NAS / SEAF SMC procedure (i.e., start again from step 7a). Alternatively, the endpoint can include a NAS / SEAF SMC retry instruction in the NAS / SEAF SMC rejection message to trigger the SEAF to re-initiate the NAS / SEAF SMC procedure.
[0478] It is worth noting that through steps 7a-8a, the 6G system can detect the DoS supply during the initial authentication of the terminal, thereby enabling the 6G system to determine to discard the tampered message and redo the protection.
[0479] As shown in Figure 4B, Figure 4B is a schematic diagram of an authentication process based on 6G AKA according to an exemplary embodiment.
[0480] 1. When UDM or ARPF receives the terminal authentication information retrieval request message sent by AUSF and initiates authentication of the terminal, UDM generates a 6G AV and sends a terminal authentication information retrieval response message (Nudm_UEAuthentication_Get Response) to AUSF. This terminal authentication information retrieval response message includes the AV and an indication that the AV will be used for 6G AKA.
[0481] 2. Export K from AUSF AUSF And based on K AUSF Generate K SEAF Then K SEAF Stored in 6G AV.
[0482] 3. AUSF sends a terminal authentication response message (Nausf_UEAuthentication_Authenticate Response) to SEAF. This terminal authentication response message includes a 6G AV, which consists of four parameters: a random number (RAND), an authentication token (AUTN), a desired hash response (HXRE*), and K. SEAF .
[0483] 4. When SEAF receives K SEAF SEAF can select a matching security algorithm based on the terminal's security capabilities received during the initial authentication process and SEAF's own security capabilities, and then base its selection on the selected security algorithm and K. SEAF Export the NAS / SEAF security context. After establishing the NAS / SEAF security context, SEAF activates NAS / SEAF integrity protection before sending NAS / SEAF SMC messages.
[0484] 5. SEAF sends a NAS / SEAF SMC message to the terminal. This NAS / SEAF SMC message may include a NAS / SEAF authentication request, which may include a random number and authentication token from 6G AV. The replay of the terminal's security capabilities, the selected security algorithm, and the method used to identify K... SEAF ngKSI.
[0485] In some embodiments, the NAS / SEAF SMC message may include the endpoint security capabilities for replay, the selected security algorithm, and information for identifying K. SEAF ngKSI.
[0486] In some embodiments, the NAS / SEAF SMC message may also include a flag requesting a complete initial NAS message.
[0487] In some embodiments, the NAS / SEAF SMC message may include the MAC value of the NAS / SEAF SMC message. In one embodiment, SEAF may use K based on the ngKSI indication. SEAF The NAS / SEAF integrity key is used to perform integrity protection on NAS / SEAF SMC messages to obtain the MAC value of the NAS / SEAF SMC messages.
[0488] 6. When the terminal receives a NAS / SEAF SMC message containing a NAS / SEAF authentication request and a MAC value, the terminal can export the K value in the same way as in step 2 (AUSF). AUSF And based on K AUSF Generate K SEAFThen the terminal verifies the NAS / SEAF SMC message.
[0489] In some embodiments, before verifying the NAS / SEAF SMC message, the terminal uses a selected security algorithm from K SEAF Export the NAS / SEAF security context indicated by ngKSI.
[0490] In some embodiments, the terminal's verification of NAS / SEAF SMC messages may include: verifying whether the terminal's stored terminal security capabilities match the terminal security capabilities sent by SEAF, and using the NAS / SEAF integrity key and NAS / SEAF integrity algorithm exported by the terminal to verify the integrity of the NAS / SEAF SMC messages.
[0491] In some embodiments, if the integrity verification of the NAS / SEAF SMC message is successful, the terminal can further verify the freshness of the received random number and authentication token. If the terminal successfully verifies the random number and authentication token, the terminal calculates RES and RES* based on RES. At this point, the terminal can consider the network authentication successful, and the terminal can activate NAS / SEAF integrity protection and confidentiality protection using the NAS / SEAF security context indicated by ngKSI.
[0492] In some embodiments, if the integrity verification of the NAS / SEAF SMC message fails, the terminal may assume that the NAS / SEAF SMC message has been tampered with by an attacker and discard the received NAS / SEAF SMC message. Based on the integrity verification in this step, a DoS attack during the terminal's initial authentication can be detected.
[0493] 7. If the integrity verification of the NAS / SEAF SMC message is successful, the terminal sends a protected NAS / SEAF SMC completion message to SEAF. This NAS / SEAF SMC completion message also includes a NAS authentication response containing RES*.
[0494] In some embodiments, the NAS / SEAF SMC completion message is protected for integrity and confidentiality by the endpoint using the NAS / SEAF security context.
[0495] In some embodiments, if the NAS / SEAF SMC message includes a flag requesting a complete initial NAS message, the NAS / SEAF SMC completion message sent by the endpoint may include the complete initial NAS message. It is worth noting that from this step onwards, all messages between the endpoint and SEAF are protected by the NAS / SEAF security context.
[0496] If the integrity verification of the NAS / SEAF SMC message fails, the endpoint can send a NAS / SEAF SMC rejection message to the SEAF. When the SEAF receives the NAS / SEAF SMC rejection message, it can re-initiate the NAS / SEAF SMC procedure (i.e., start from step 4 again). Alternatively, the endpoint can include a NAS / SEAF SMC retry instruction in the NAS / SEAF SMC rejection message to trigger the SEAF to re-initiate the NAS / SEAF SMC procedure.
[0497] In some embodiments, if the integrity verification of the NAS / SEAF SMC message fails again after the NAS / SEAF SMC process is re-initiated, the terminal may consider the first authentication to have failed, send a NAS / SEAF SMC rejection message to SEAF without a NAS / SEAF SMC retry instruction, and skip the remaining steps in Figure 6B.
[0498] 8. SEAF calculates HRES* based on RES* and compares HRES* with HXRES*. If HRES* and HXRES* match, SEAF considers the terminal's initial authentication successful from the perspective of the serving network.
[0499] 9. SEAF sends the RES* received from the terminal to AUSF via the terminal authentication request message.
[0500] 10. When AUSF receives a terminal authentication request message including RES*, AUSF compares the received RES* with the stored XRES*. If RES* and HRES* are related, AUSF can consider the terminal's first authentication to be successful from the perspective of the home network.
[0501] 11. AUSF indicates to SEAF via the terminal authentication response message whether the terminal's initial authentication was successful from the perspective of the home network.
[0502] It is worth noting that through steps 4-7, the 6G system can detect DoS attacks during the initial authentication of the terminal, thereby enabling the 6G system to determine whether to discard the tampered message and redo the protection.
[0503] In some embodiments, when SEAF and the terminal are respectively based on K SEAF Export the NAS / NF security context (including the integrity key K used for integrity protection). SEAFint and the confidentiality key K used for confidentiality protection SEAFenc When using ), the following parameters are required to form the string S.
[0504] FC = To Be Dertermined (TBD);
[0505] P0 = Algorithm type distinguisher. For example, the value of the algorithm type distinguisher is different for integrity algorithms and encryption algorithms.
[0506] L0 = Length of the algorithm type distinguisher;
[0507] P1 = Algorithm identifier, typical algorithm identifiers may include, but are not limited to, the ID of AES, the ID of ZUC, etc.
[0508] L1 = Length of the algorithm identifier;
[0509] The input key is a 256-bit key. SEAF .
[0510] In some embodiments, SEAF receives K from AUSF SEAF Export K SEAF ′, and in the export of K SEAF 'After deleting K' SEAF The terminal can export K in the same way as SEAF. SEAF Export K SEAF This is for communication with K sent from the home network to the serving network. SEAF The current processing remains consistent, based on K after the terminal's initial authentication. SEAF Export K AMF K was then deleted for security and isolation purposes. SEAF .
[0511] In some embodiments, when SEAF and the terminal are respectively based on K SEAF Export K SEAF When using ', the following parameters are needed to form the string S.
[0512] FC = To Be Dertermined (TBD);
[0513] P0 = ngKSI;
[0514] L0 = the length of ngKSI;
[0515] The input key is a 256-bit key. SEAF .
[0516] In some embodiments, the operations that the terminal can perform include, but are not limited to, at least one of the following:
[0517] The terminal receives and parses NAS / SEAF SMC messages from SEAF.
[0518] The terminal can derive K based on the ngKSI contained in the NAS / SEAF SMC message. SEAF And based on K SEAF Export the NAS / SEAF security context.
[0519] The terminal can use the exported NAS / SEAF security context to verify the integrity of NAS / SEAF SMC messages.
[0520] The terminal can perform corresponding processing after verifying the integrity of the NAS / SEAF SMC message, such as sending a protected NAS / SEAF SMC complete message or an unprotected NAS / SEAF SMC reject message.
[0521] The terminal is able to include a NAS / SEAF SMC retry instruction in the NAS / SEAF SMC rejection message.
[0522] The terminal can be from K SEAF Export K SEAF ′, and from K SEAF Export NAS / SEAF security context.
[0523] The terminal can use the received ngKSI from K SEAF Export K SEAF ′.
[0524] In some embodiments, the operations that SEAF can perform include, but are not limited to, at least one of the following:
[0525] SEAF can receive K sent by AUSF SEAF It was then decided to initiate the NAS / SEAF SMC process.
[0526] SEAF can receive K SEAF Export the NAS / SEAF security context.
[0527] SEAF can send a message to the terminal containing information for identifying K. SEAF The NAS / SEAF SMC message includes ngKSI, EAP success information, replay endpoint security capabilities, selected security algorithm, and a flag indicating the completion of the initial NAS message request.
[0528] Upon receiving a NAS / SEAF SMC response message from the terminal, SEAF performs corresponding processing. For example, it continues the protected initial authentication process, or if it receives a NAS / SEAF SMC rejection message containing a NAS / SEAF SMC retry instruction, SEAF re-initiates the NAS / SEAF SMC process to the terminal, or if the re-initiated NAS / SEAF SMC process fails, SEAF terminates the terminal's initial authentication.
[0529] SEAF can from K SEAF Export K SEAF ′, and from K SEAF Export NAS / SEAF security context.
[0530] SEAF can use the assigned indicator K SEAF ngKSI from K SEAF Export K SEAF ′.
[0531] This disclosure also provides apparatus (also referred to as communication equipment, etc.) for implementing any of the above methods. For example, an apparatus is provided, which includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is provided, including units or modules for implementing the steps performed by a network device (e.g., access network device, core network functional node, or core network equipment, etc.) in any of the above methods.
[0532] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0533] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0534] Figure 5A is a schematic diagram of the structure of a network device according to an exemplary embodiment. As shown in Figure 5A, the network device 5100 includes: a first processing module 5101 configured to generate a second key based at least on a first key; the first key is provided by a second node, and the first key is a shared key generated by the second node during the initial authentication of the terminal; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal. Optionally, the first processing module 5101 is used to instruct the first node to perform at least one of the information processing-related steps (e.g., steps S2102, S2103, S2202, S2203, S2204, S3101, S3202, but not limited thereto) in any of the above data security processing methods, which will not be elaborated here. Optionally, the network device 5100 may further include a second transceiver module, which is used to perform at least one of the communication steps such as sending and / or receiving performed by the first node in any of the above data security processing methods (e.g., steps S2101, S2104, S2201, S2205, S3102, S3201, S3203, but not limited thereto), which will not be elaborated here.
[0535] Figure 5B is a schematic diagram of a terminal structure according to an exemplary embodiment. As shown in Figure 5B, the terminal 5200 includes: a second processing module 5201 configured to generate a second key based at least on a first key; the first key is a shared key generated by the terminal during initial authentication; the second key is used at least to protect the communication security between the terminal and the first node during the terminal's initial authentication. Optionally, the second processing module 5201 is used to instruct the terminal to perform at least one of the information processing-related steps (e.g., steps S2105, S2106, S2107, S2206, S2207, S2208, S2209, S3103, S3204, but not limited thereto) in any of the above data security processing methods, which will not be elaborated here. Optionally, the terminal 5200 may further include a third transceiver module, which is used to perform at least one of the communication steps such as sending and / or receiving performed by the terminal in any of the above data security processing methods (e.g., steps S2104, S2205, S3102, and S3203, but not limited thereto), which will not be described in detail here.
[0536] Figure 5C is a schematic diagram of a network device according to an exemplary embodiment. As shown in Figure 5C, the network device 5300 includes: a first transceiver module 5301 configured to send a fourth message to a first node; the fourth message is a response message to a terminal authentication request message, the fourth message includes a first key, the first key is a shared key generated during the initial authentication of the terminal by the second node, the first key is used by the first node to generate a second key; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal. Optionally, the first transceiver module 5301 is used to instruct the second node to perform at least one of the communication steps such as sending and / or receiving in any of the above data security processing methods (e.g., steps S2101, S2201, and S3201, but not limited thereto), which will not be elaborated here. Optionally, the network device 5300 may also include a third processing module, the third processing module being used to perform at least one of the information processing-related steps performed by the second node in any of the above data security processing methods, which will not be elaborated here.
[0537] Figure 6A is a schematic diagram illustrating the structure of a communication device 6100 according to an exemplary embodiment. The communication device 6100 can be a network device (e.g., an access network device or a core network device), a terminal (e.g., a user equipment), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above data security processing methods. The communication device 6100 can be used to implement the data security processing methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0538] As shown in Figure 6A, the communication device 6100 is used to execute any of the above methods. The communication device 6100 includes one or more processors 6101. The processor 6101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 6100 is used to execute any of the above methods. Optionally, one or more processors 6101 are used to invoke instructions to cause the communication device 6100 to execute any of the above methods.
[0539] In some embodiments, the communication device 6100 further includes one or more transceivers 6103. When the communication device 6100 includes one or more transceivers 6103, the transceivers 6103 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2104, S2201, S2205, S3102, S3201, S3203, but not limited thereto), and the processor 6101 performs at least one of other steps (e.g., steps S2102, S2103, S2105, S2106, S2107, S2202, S2203, S2204, S2206, S2207, S2208, S2209, S3101, S3103, S3202, S3204, but not limited thereto). In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.
[0540] In some embodiments, the communication device 6100 further includes one or more memories 6102 for storing data and / or instructions. Optionally, one or more processors 6101 are used to invoke instructions stored in the memory 6102 to cause the communication device 6100 to perform any of the above methods. Optionally, all or part of the memory 6102 may also be located outside the communication device 6100. In an optional embodiment, the communication device 6100 may include one or more interface circuits 6104. Optionally, the interface circuit 6104 is connected to the memory 6102 and can be used to receive data and / or instructions from the memory 6102 or other devices, and can be used to send data and / or instructions to the memory 6102 or other devices. For example, the interface circuit 6104 can read data and / or instructions stored in the memory 6102 and send the data and / or instructions to the processor 6101. Optionally, the communication device 6100 further includes one or more interface circuits 6104 connected to the memory 6102. The interface circuits 6104 can be used to receive data and / or instructions from the memory 6102 or other devices, and can be used to send data and / or instructions to the memory 6102 or other devices. For example, the interface circuit 6104 can read data and / or instructions stored in the memory 6102 and send the data and / or instructions to the processor 6101.
[0541] The communication device 6100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 6100 described in this disclosure is not limited thereto, and the structure of the communication device 6100 may not be limited by FIG. 6A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection having one or more ICs, optionally, the IC collection may also include storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0542] Figure 6B is a schematic diagram of a chip 6200 according to an exemplary embodiment. For cases where the communication device 6100 can be a chip or a chip system, the schematic diagram of the chip 6200 shown in Figure 6B can be referenced, but is not limited thereto.
[0543] Chip 6200 includes one or more processors 6201. Chip 6200 is used to perform any of the methods described above.
[0544] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data and / or instructions. Optionally, all or part of the memories 6203 may be located outside of chip 6200. Optionally, interface circuit 6202 is connected to memory 6203, and interface circuit 6202 can be used to receive data and / or instructions from memory 6203 or other devices, and interface circuit 6202 can be used to send data and / or instructions to memory 6203 or other devices. For example, interface circuit 6202 can read data and / or instructions stored in memory 6203 and send the data and / or instructions to processor 6201.
[0545] In some embodiments, the interface circuit 6202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2104, S2201, S2205, S3102, S3201, S3203, but not limited thereto). For example, the interface circuit 6202 performing the communication steps such as sending and / or receiving in the above method means that the interface circuit 6202 performs data and / or instruction interaction between the processor 6201, the chip 6200, the memory 6203, or the transceiver device. In some embodiments, the processor 6201 performs at least one of other steps (e.g., steps S2102, S2103, S2105, S2106, S2107, S2202, S2203, S2204, S2206, S2207, S2208, S2209, S3101, S3103, S3202, S3204, but not limited thereto).
[0546] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0547] This disclosure also provides a storage medium storing instructions that, when executed on a communication device 6100, cause the communication device 6100 to perform any of the methods described above. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but it can also be a storage medium readable by other devices. Optionally, the storage medium can be a non-transitory storage medium, but it can also be a temporary storage medium.
[0548] This disclosure also provides a program product, including a program and / or instructions, which, when executed by a communication device 6100, cause the communication device 6100 to perform any of the above communication methods. Optionally, the above program product is a computer program product.
[0549] This disclosure also provides a computer program that, when run on a computer, causes the computer to perform any of the above communication methods.
[0550] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.
[0551] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A data security processing method, wherein, Executed by the first node, the method includes: A second key is generated based on at least a first key; the first key is a shared key generated during the initial authentication of the terminal by the second node; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
2. The method according to claim 1, wherein, The generation of the second key based at least on the first key includes one of the following: The second key is generated based on the first key and the first security algorithm; wherein the first security algorithm is determined by the first node based on first information and second information, the first information being used to indicate the security algorithms supported by the terminal; and the second information being used to indicate the security algorithms supported by the first node. The second key is generated based on the third key and the first security algorithm; the third key is generated by the first node based on the first key and third information, and the third information is used to identify the security context derived from the first key.
3. The method according to claim 1 or 2, wherein, The method further includes: A first message is sent to the terminal; the first message is used to trigger the terminal to generate the second key.
4. The method according to claim 3, wherein, The first message is used by the terminal to determine a first security algorithm, and the first security algorithm is used by the terminal to generate the second key.
5. The method according to claim 3 or 4, wherein, The first message is a message whose integrity is protected by the first node using the second key.
6. The method according to any one of claims 3 to 5, wherein, The first message includes at least one of the following: The third information is used to identify the security context derived from the first key; the third information is at least used by the terminal to generate the third key. The fourth piece of information is used to identify the first security algorithm; The first security algorithm is used by the terminal to generate the second key; The fifth piece of information is used to indicate the first verification value; The first verification value is a message verification value obtained by the first node using the second key to protect the integrity of the first message. The first verification value is used by the terminal to verify the integrity of the first message. The first information is used to indicate the security algorithm supported by the terminal; the first information is also used by the terminal to determine whether the security algorithm supported by the terminal sent to the first node has been tampered with. The sixth piece of information is used to indicate that the second node has successfully authenticated the terminal's identity; The seventh piece of information is used to request the terminal to authenticate its identity with the network; The seventh piece of information includes: a first random number and an authentication token.
7. The method according to claim 6, wherein, The method further includes: The terminal receives a second message; the second message is a message sent by the terminal after successfully verifying the integrity of the first message, and the second message is a message protected by the terminal using the second key.
8. The method according to claim 7, wherein, The second message includes: an eighth message, which indicates a first authentication response value; the first authentication response value is used by the first node to authenticate the terminal; the first authentication response value is generated by the terminal based on the first random number after the authentication token is successfully verified; wherein, the first message includes the seventh message.
9. The method according to any one of claims 3 to 6, wherein, The method further includes: The terminal sends a third message; the third message is sent by the terminal after the integrity verification of the first message fails, and the third message is used to trigger the first node to resend the first message to the terminal.
10. The method according to any one of claims 1 to 9, wherein, The method further includes: Receive a fourth message sent by the second node; the fourth message is a response message to the terminal authentication request message, and the fourth message includes the first key.
11. The method according to claim 10, wherein, The fourth message includes an authentication vector; the authentication vector is used for the terminal to authenticate its identity with the network, and the authentication vector includes the first key.
12. A data security processing method, wherein, The method, executed by a terminal, includes: A second key is generated based on at least a first key; the first key is a shared key generated by the terminal during the initial authentication; the second key is used at least during the initial authentication of the terminal to protect the communication security between the terminal and the first node.
13. The method according to claim 12, wherein, The method further includes: The terminal receives a first message sent by the first node, and the first message triggers the terminal to generate the second key.
14. The method according to claim 13, wherein, The first message is used by the terminal to determine a first security algorithm, and the first security algorithm is used by the terminal to generate the second key.
15. The method according to claim 14, wherein, The generation of the second key based at least on the first key includes one of the following: The second key is generated based on the first key and the first security algorithm; The second key is generated based on the third key and the first security algorithm; The third key is generated by the first node based on the first key and the third information, and the third information is used to identify the security context derived from the first key.
16. The method according to any one of claims 13 to 15, wherein, The first message is a message whose integrity is protected by the first node using the second key.
17. The method according to any one of claims 13 to 16, wherein, The first message includes at least one of the following: The third piece of information is used to identify the security context derived from the first key; The fourth piece of information is used to identify the first security algorithm; The fifth piece of information is used to indicate the first verification value; the first verification value is a message verification value obtained by the first node using the second key to perform integrity protection on the first message, and the first verification value is used by the terminal to perform integrity verification on the first message; The first piece of information is used to indicate the security algorithms supported by the terminal; The first information is used by the terminal to determine whether the security algorithm supported by the terminal and sent to the first node has been tampered with; The sixth piece of information is used to indicate that the second node has successfully authenticated the terminal's identity; The seventh piece of information is used to request the terminal to authenticate its identity with the network; The seventh piece of information includes: a first random number and an authentication token.
18. The method according to claim 17, wherein, The method further includes: Determine a second verification value; the second verification value is a message verification value obtained by the terminal using the second key to perform integrity protection on the first message; Based on the second verification value and the first verification value, the integrity verification result of the first message is determined; wherein, the first message includes the fifth information.
19. The method according to claim 17 or 18, wherein, The method further includes: Send a second message to the first node; the second message is a message sent by the terminal after successfully verifying the integrity of the first message, and the second message is a message protected by the terminal using the second key.
20. The method according to claim 19, wherein, The second message includes: an eighth message, which indicates a first authentication response value; the first authentication response value is used by the first node to authenticate the terminal; the first authentication response value is generated by the terminal based on the first random number after the authentication token is successfully verified; wherein, the first message includes the seventh message.
21. The method according to claim 17 or 18, wherein, The method further includes: A third message is sent to the first node; the third message is a message sent by the terminal after the integrity verification of the first message fails, and the third message is used to trigger the first node to resend the first message to the terminal.
22. A data security processing method, wherein, Executed by the second node, the method includes: A fourth message is sent to the first node; the fourth message is a response message to the terminal authentication request message, the fourth message includes a first key, the first key is a shared key generated by the second node during the initial authentication of the terminal, the first key is used by the first node to generate a second key; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal.
23. The method according to claim 22, wherein, The fourth message includes an authentication vector, which is used by the terminal to authenticate its identity with the network.
24. A data security processing method, wherein, Performed by a communication system, the method includes: The first node generates a second key based on at least a first key; the first key is provided by the second node and is a shared key generated by the second node during the initial authentication of the terminal; the second key is used at least to protect the communication security between the terminal and the first node during the initial authentication of the terminal. The first node sends a first message to the terminal; the first message is used to trigger the terminal to generate the second key; The terminal generates a second key based on at least the first key.
25. A communication device, wherein, The communication device is used to perform the data security processing method according to any one of claims 1 to 11, 12 to 21, 22 or 23.
26. A communication system, wherein, The communication system includes a terminal and a first node; wherein... The first node is configured to implement the data security processing method according to any one of claims 1 to 11; The terminal is configured to implement the data security processing method according to any one of claims 12 to 21.
27. A storage medium, wherein, The storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the data security processing method according to any one of claims 1 to 11, 12 to 21, 22, or 23.
28. A computer program product comprising a computer program that, when executed by a processor, implements the data security processing method according to any one of claims 1 to 11, 12 to 21, 22, or 23.
Citation Information
Patent Citations
Key generation method, terminal device and network device
CN111404669A
Authentication information processing method, terminal and network equipment
CN111835691A
Authentication of a Communications Device
US20210400475A1
Method, UE, and network entity for handling synchronization of security key in wireless network
US20230370840A1
Method and device for terminal authentication in wireless communication system
WO2023153578A1