Arithmetic device, arithmetic method, communication system, and program
By employing encryption processes like Rocca-S and AEGIS-256 to protect sequence numbers, the vulnerability of sequence number exposure in wireless communication systems is mitigated, ensuring secure and private mutual authentication.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- KDDI CORP
- Filing Date
- 2025-10-30
- Publication Date
- 2026-05-15
AI Technical Summary
Existing wireless communication systems face vulnerabilities in protecting the privacy of sequence numbers, which can be exploited by attackers to determine the duration of stay, compromising individual privacy.
Implement encryption processes, such as Rocca-S and AEGIS-256, to protect sequence numbers by making key erasure impossible and ensuring reversibility, using operations like Enc(AK, SQN) instead of SQN(XOR)AK in authentication token calculations.
Enhances security by preventing key erasure and reducing the risk of sequence number leakage, thereby safeguarding individual privacy during mutual authentication.
Smart Images

Figure JP2025038186_15052026_PF_FP_ABST
Abstract
Description
Computing device, computing method, communication system, and program
[0001] The present invention relates to a computing device, a computing method, a communication system, and a program. This application claims priority from Japanese Patent Application No. 2024-193538 filed in Japan on November 5, 2024, the content of which is incorporated herein by reference.
[0002] Conventionally, a wireless communication system including a terminal device and a network is known. Usually, when starting new information communication between such a terminal device and a network, mutual authentication is performed. For example, Non-Patent Document 1 defines specific specifications for such mutual authentication.
[0003] In such specific specifications of mutual authentication, first, a serving network (SN) having a visitor location register (VLR) transmits an authentication data request to a home environment (HE) having a home location register (HLR), and the home environment responds thereto by returning an authentication data response consisting of a batch of authentication vectors. Next, in order to execute authentication between the serving network (SN) and the mobile station (MS), the serving network (SN) transmits a user authentication request. When a user authentication request is made, an authentication token AUTN is calculated.
[0004] The calculation of the authentication token AUTN includes the exclusive logical sum of a sequence number (SQN; sequence number) formed in the home environment and an authentication key (AK). Here, Non-Patent Document 2 reports the security vulnerability when performing an exclusive logical sum operation using the sequence number and the authentication key (AK).
[0005] 3GPP, "TS 33.102", v18.0.0 Ya-Chu Cheng et al., A New Tracking-Attack Scenario Based on the Vulnerability and Privacy Violation of 5G AKA Protocol, IEEE Access
[0006] Specifically, if an attacker intercepts an authentication token containing a sequence number transmitted from the network, they can erase the key by performing an exclusive OR operation again. In other words, since an attacker can obtain the sequence number from the authentication token, there is a possibility that the sequence number information will be leaked. Initially, sequence numbers were not considered highly confidential information. However, because it is possible to determine the duration of stay from the sequence number, there is a need to protect sequence numbers as information related to individual privacy.
[0007] This invention has been made in consideration of these circumstances, and its objective is to provide a computing device, a computing method, a communication system, and a program that can realize a mutual authentication method that can protect information concerning the privacy of persons operating terminal devices.
[0008] (1) One aspect of the present invention is a computing device that performs calculations in communication between a terminal device and a network, and uses a given key and information relating to the privacy of the person operating the terminal device, and performs calculations in a manner that makes it impossible to erase the key and is reversible. (2) Another aspect of the present invention is the computing device of (1) described above, wherein the calculation is used to derive AUTON or AUTOS. (3) Another aspect of the present invention is the computing device of (1) or (2) described above, wherein the information relating to the privacy of the person operating the terminal device is a sequence number. (4) Another aspect of the present invention is the computing device of any of (1) to (3) described above, wherein the method that makes it impossible to erase the key and is reversible is an encryption process. (5) Another aspect of the present invention is the computing device of (4) described above, wherein the encryption process is Rocca-S. (6) In addition, one aspect of the present invention is a computing device according to any of (1) to (5) above, wherein the network is a function for user authentication. (7) In addition, one aspect of the present invention is a computing method for performing calculations in communication between a terminal device and a network, wherein the calculation is performed using a given key and information relating to the privacy of a person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible. (8) In addition, one aspect of the present invention is a communication system comprising a terminal device and a network, wherein in communication between the terminal device and the network, the calculation is performed using a given key and information relating to the privacy of a person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible. (9) In addition, one aspect of the present invention is a program for causing a computer to perform calculations in communication between a terminal device and a network, wherein the program causes a computer to perform a calculation step using a given key and information relating to the privacy of a person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible.
[0009] According to the present invention, it is possible to provide a computing device, a computing method, and a communication system that can realize a mutual authentication method capable of protecting information regarding the privacy of persons operating terminal devices.
[0010] This figure shows a schematic network architecture of a wireless communication system according to one embodiment. This is a first flowchart showing the mutual authentication flow of the wireless communication system according to this embodiment. This is a first schematic diagram showing an example of calculations in the authentication center according to this embodiment. This is a second flowchart showing the mutual authentication flow of the wireless communication system according to this embodiment. This is a second schematic diagram showing an example of calculations in the authentication center according to this embodiment. This is a block diagram showing an example of the internal configuration of the arithmetic unit according to this embodiment.
[0011] [Embodiments] Preferred embodiments of the computing device, computing method, communication system, and program according to aspects of the present invention will be described in detail below with reference to the attached drawings. It should be noted that the embodiments of the present invention are not limited to these embodiments, and include various modifications or improvements. In other words, the components described below include those that are easily conceivable by those skilled in the art, and those that are substantially the same, and the components described below can be combined as appropriate. Furthermore, various omissions, substitutions, or modifications of components can be made without departing from the spirit of the present invention. Also, in the following drawings, the scale and number of components in each structure may differ from the scale and number of components in the actual structure in order to make each structure easier to understand.
[0012] In the following description, for the sake of clarity, terms and names defined in the IETF (Internet Engineering Task Force), 3GPP (registered trademark), and LTE (3rd Generation Partnership Project Long Term Evolution) standards may be used. However, this embodiment is not limited by such terms and names and is applicable to systems based on other standards.
[0013] [Wireless Communication System] Figure 1 is a diagram showing a schematic network architecture of a wireless communication system according to one embodiment. First, with reference to the figure, the schematic of a wireless communication system to which the calculation method and calculation device according to this embodiment are applied will be described. As an example, the figure shows a 5G network architecture. In the example described below, a wireless communication system will be described, but the communication system according to this embodiment is also applicable to wired communication systems.
[0014] The network elements of a 5G network architecture include User Equipment (UE). In the following description, UE may be referred to as user equipment, user terminal, user device, terminal device, or simply terminal, etc. UE may also include smartphones, tablet devices, wearable devices, etc.
[0015] The network architecture shown in the figure further includes a Radio Access Network (RAN), Access and Mobility Function (AMF), Unified Data Management (UDM), Authentication Server Function (AUSF), Security Anchor Function (SEAF), and the like.
[0016] The primary function of a RAN (Local Area Network) is to control users for wireless access to a mobile communication network. Conceptually, a RAN is contained between devices (e.g., smartphones, computers, or any remote controllers) and provides connectivity between these devices to the core network.
[0017] AMF network elements are responsible for terminal access management and mobility management, such as registration management, connection management, mobility management, and reachability management. In practical applications, AMF network elements include mobility management functions within the LTE network framework of a Mobility Management Entity (MME), and further include access management functions.
[0018] The SEAF network element is configured to complete authentication to the UE. In 5G, the SEAF functionality may be combined with the AMF, as shown in the diagram.
[0019] The AUSF network element has authentication server functionality and is configured to respond to authentication requests made by the SEAF network element. During the authentication process, the AUSF network element receives the authentication vector sent from the UDM, processes the authentication vector, and sends the processed authentication vector to SEAF.
[0020] The UDM network element may store the user's subscription information and may generate authentication parameters, etc.
[0021] An ARPF network element has an authentication information repository and processing functions, and is configured to store the user's long-term authentication information, such as key K. In 5G, the functions of the ARPF network element may be combined with a UDM network element.
[0022] [Procedure for sharing authentication keys] The procedure for sharing authentication keys will be explained with reference to Figures 2 and 3.
[0023] Figure 2 is a first flowchart showing the mutual authentication flow of the wireless communication system according to this embodiment. The figure shows the authentication key sharing protocol in 3GPP (registered trademark). The figure shows the exchange of information between the Mobile Station (MS), Visitor Location Register (VLR) / Serving Network (SN), and Home Environment (HE) / Home Location Register (HLR). In the following description, MS may also be referred to as the terminal device, SN / VLR and HE / HLR as the network, and HE / HLR as the authentication center.
[0024] (Step S111) First, the SN / VLR requests authentication data from the HE / HLR.
[0025] (Step S112) When HE / HLR receives an authentication data request from SN / VLR, it generates one or more (for example, N, where N is an integer greater than or equal to 1) authentication vectors AV(1...N).
[0026] (Step S113) The HE / HLR responds to the SN / VLR with one or more generated authentication vectors AV(1...N) (Authentication Data Response).
[0027] (Step S114) The SN / VLR stores one or more authentication vectors obtained from the HE / HLR upon request.
[0028] Furthermore, the process from step S111 to step S114 can also be described as the process of distributing the authentication vector from HE to SN.
[0029] (Step S115) The SN / VLR selects an authentication vector AV(i) from among the stored authentication vectors AV(1...N).
[0030] (Step S116) The SN / VLR requests user authentication from the MS. In the user authentication request, the SN / VLR sends a random challenge RAND(i) and an authentication token AUTN(i) to the MS (User Authentication Request). The authentication token AUTN(i) will be described later with reference to Figure 3.
[0031] (Step S117) The MS verifies whether it can accept the authentication token AUTN(i). If the MS can accept the authentication token AUTN(i), it computes the response RES(i).
[0032] (Step S118) The response RES(i) calculated by MS is sent back to SN / VLR as a User Authentication Response.
[0033] (Step S119) The MS further computes a Cipher Key CK(i) and an Integrity Key IK(i).
[0034] (Step S120) The SN / VLR compares the received response RES(i) with XRES.
[0035] (Step S121) If RES(i) and the Expected Response (XRES) match, the SN / VLR determines that authentication and key agreement exchange are complete and selects the Cipher Key (CK(i)) and the Integrity Key (IK(i)).
[0036] Furthermore, the steps from step S115 to step S121 can also be described as the authentication and key establishment steps.
[0037] Figure 3 is a first schematic diagram showing an example of calculations in the authentication center according to this embodiment. In the authentication center, calculations as shown in the figure are performed. f1 and f2 are message authentication functions. f3, f4 and f5 are key generation functions.
[0038] In this case, the message authentication code MAC (Message Authentication Code) can be represented by the following mathematical formula (1).
[0039] MAC = f1K(SQN || RAND || AMF)...(1)
[0040] Also, the expected response XRES can be represented by the following mathematical formula (2).
[0041] XRES = f2K(RAND)...(2)
[0042] Also, the cipher key CK for encryption can be represented by the following mathematical formula (3).
[0043] CK = f3K(RAND)...(3)
[0044] Also, the integrity key IK for authentication can be represented by the following mathematical formula (4).
[0045] IK = f4K(RAND)...(4)
[0046] Also, the anonymity key AK can be represented by the following mathematical formula (5).
[0047] AK = f5K(RAND)...(5)
[0048] The authentication token AUTN can be represented by the following mathematical formula (6) using the sequence number SQN and the anonymity key AK.
[0049]
[0050] Here, as described in Non-Patent Document 2 mentioned above, an attacker can obtain the sequence number by utilizing the following formula (7) and deriving it.
[0051]
[0052] In other words, if an attacker intercepts an authentication token containing a sequence number transmitted from the network, they can erase the key by performing an exclusive OR operation again, potentially leading to the leakage of sequence number information. Initially, sequence numbers were not considered highly confidential information, but because it is possible to determine the duration of stay from sequence numbers, there has been a demand to protect sequence numbers as information related to the privacy of those operating terminal devices.
[0053] Therefore, according to this embodiment, an authentication token AUTN is calculated using a given anonymous key AK and a sequence number (which can also be said to be information related to the privacy of the person operating the terminal device) in a way that makes it impossible to erase the key and is reversible. Conventionally, since the problem of protecting the sequence number was not anticipated, the relatively lightweight operation of exclusive OR has been used. Conventionally, the exclusive OR used in calculations is reversible, but it is an operation that allows the key to be erased.
[0054] Encryption can be used as an example of an operation that is impossible to erase and is reversible. Specifically, in the calculation of the authentication token AUTN, by performing the operation Enc(AK, SQN) instead of SQN(XOR)AK, the attack described in Non-Patent Literature 2 can be prevented. Enc(AK, SQN) is the encryption process of the sequence number SQN using the secret key AK.
[0055] Specifically, one example of encryption processing is the algorithm defined as f8. Another example is the use of a proprietary symmetric-key algorithm tailored to the length of the sequence number SQN. More specific examples of encryption processing include Rocca-S and AEGIS-256. Note that the operations according to this embodiment are not limited to such encryption processing, and other operations that make key erasure impossible and are reversible may also be used. Operations that make key erasure impossible and are reversible may include, for example, matrix transformations.
[0056] This process is performed on both the receiving and transmitting sides of the AUTN. Specifically, if the operation Enc(AK, SQN) is performed instead of SQN(XOR)AK, the sequence number SQN is decrypted by decrypting the encrypted document. This improves security without affecting other parts of the current 3GPP®.
[0057] [Resynchronization Procedure] Next, the resynchronization procedure will be explained with reference to Figures 4 and 5. During resynchronization, AUTOS is used instead of the authentication token AUTON. Since SQN(XOR)AK is also used in AUTOS, there is a possibility of being subjected to the attack described in Non-Patent Document 2. Therefore, in this embodiment, even during resynchronization, AUTOS is generated by performing an operation that makes it impossible to erase the key and is reversible, instead of using SQN(XOR)AK.
[0058] Figure 4 is a second flowchart showing the mutual authentication flow of the wireless communication system according to this embodiment. This figure shows the resynchronization protocol in 3GPP®. This figure shows the exchange of information between the Mobile Station (MS), the Serving Network (SN), and the Home Environment (HE).
[0059] (Step S211) This step corresponds to step S116, which was described with reference to Figure 2. SN makes a user authentication request to MS.
[0060] (Step S212) Here, if synchronization fails, MS sends an AUTOS message to SN. The AUTOS message will be described later with reference to Figure 5.
[0061] (Step S213) When SN receives a synchronization failure message including AUTOS from MS, it sends an authentication data request including a synchronization failure instruction (Sync Failure ind) to HE along with the parameters RAND and AUTOS.
[0062] (Step S214) When HE receives such an authentication data request, including a synchronization failure ind, it sends an authentication data response to SN. The authentication data response includes an authentication vector.
[0063] Figure 5 is a second schematic diagram showing an example of a calculation in the authentication center according to this embodiment. In the authentication center, the calculation shown in the figure is performed. As shown in the figure, the exclusive OR of the sequence number SQN and the anonymous key AK is also used in the calculation of AUTOS. As explained with reference to Figure 3, in such cases there was a problem that an attacker could guess the sequence number.
[0064] Therefore, according to this embodiment, in the calculation of AUTOS, instead of the exclusive OR operation between the sequence number SQN and the anonymous key AK, an operation that makes key erasure impossible and is reversible is used. Specifically, since the function FNC shown in the figure is an exclusive OR operation, in this embodiment, the function FNC is made into an operation that makes key erasure impossible and is reversible. As an example of a specific calculation method, it is possible to use a method similar to the one described with reference to Figure 3.
[0065] [Internal Configuration] Figure 6 is a block diagram showing an example of the internal configuration of the arithmetic unit according to this embodiment. The arithmetic unit shown in the figure is provided in at least one of the UE or the network. At least some of the functions of the arithmetic unit can be realized using a computer as shown in the figure. The computer consists of a central processing unit (processor) 901, RAM 902, input / output ports 903, input / output devices 904 and 905, etc., and a bus 906. The computer itself can be realized using existing technology. The central processing unit 901 executes instructions contained in programs read from the RAM 902, etc. The central processing unit 901 writes data to the RAM 902, reads data from the RAM 902, and performs arithmetic and logical operations according to each instruction. The RAM 902 stores data and programs. Each element included in the RAM 902 has an address and can be accessed using that address. RAM stands for "Random Access Memory". The input / output ports 903 are ports for the central processing unit 901 to exchange data with external input / output devices, etc. Input / output devices 904 and 905 are input / output devices. Input / output devices 904 and 905 exchange data with the central processing unit 901 via the input / output port 903. Bus 906 is a common communication channel used inside the computer. For example, the central processing unit 901 reads and writes data to RAM 902 via bus 906. Also, for example, the central processing unit 901 accesses input / output ports via bus 906. Furthermore, all or part of each functional unit of the network 30 or terminal device 50 may be implemented using hardware such as ASIC, PLD, or FPGA. Furthermore, all or part of each functional unit may be implemented by a combination of software and hardware.
[0066] [Summary of Embodiments] According to the embodiments described above, the calculation method according to this embodiment performs calculations in wireless communication between a terminal device and a network. Furthermore, the calculation method uses a given key (anonymous key AK) and information regarding the privacy of the person operating the terminal device (e.g., sequence number SQN) to perform calculations in a way that makes it impossible to erase the key and is reversible. By adopting such a configuration, even if an authentication token containing a sequence number transmitted from the network is intercepted, the attacker cannot erase the key, and the risk of leakage of sequence number information can be reduced.
[0067] The calculation method described above is performed by a computing device installed in the terminal device or network. This calculation is used to derive AUTON or AUTOS. Therefore, according to this embodiment, a mutual authentication method is available that can protect information regarding the privacy of the person operating the terminal device.
[0068] Furthermore, in the embodiments described above, the information relating to the privacy of the person operating the terminal device is the sequence number. Conventionally, sequence numbers were not considered highly confidential information. However, since it is possible to determine the time spent on the device based on the sequence number, there has been a need to protect the sequence number as information relating to the privacy of the person operating the terminal device. According to this embodiment, since the leakage of sequence numbers can be suppressed, information relating to an individual's privacy can be protected.
[0069] Furthermore, according to this embodiment, existing encryption processes can be used as an example of a method that makes key erasure impossible and is reversible. More specific examples of encryption processes include Rocca-S and AEGIS-256. According to this embodiment, personal and privacy-related information can be easily protected.
[0070] Furthermore, the above-described embodiment makes it possible to realize a mutual authentication method that can protect information regarding the privacy of the person operating the terminal device, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0071] Although embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments, and design modifications and the like are also included within the scope of the gist of the present invention.
[0072] Alternatively, computer programs for realizing the functions of each of the above-mentioned devices may be recorded on a computer-readable recording medium, and the programs recorded on this recording medium may be loaded into a computer system and executed. The term "computer system" here may include hardware such as an operating system and peripheral devices. Furthermore, "computer-readable recording medium" refers to writable non-volatile memory such as flexible disks, magneto-optical disks, ROMs, and flash memory, portable media such as DVDs (Digital Versatile Discs), and storage devices such as hard disks built into a computer system.
[0073] Furthermore, "computer-readable recording media" includes volatile memory (e.g., DRAM (Dynamic Random Access Memory)) within a computer system that acts as a server or client when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, which retains the program for a certain period of time. In addition, the above program may be transmitted from the computer system that stores the program in a storage device, etc., to another computer system via a transmission medium or by transmission waves within the transmission medium. Here, the "transmission medium" for transmitting the program refers to a medium that has the function of transmitting information, such as a network such as the Internet or a communication line such as a telephone line. Furthermore, the above program may be for the purpose of realizing a part of the above-mentioned functions. Moreover, it may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already recorded in the computer system.
[0074] According to the present invention, a mutual authentication method can be realized that can protect information regarding the privacy of the person operating the terminal device.
[0075] MS...Mobile Station, SN...Serving Network, VLR...Visitor Location Register, HE...Home Environment, HLR...Home Location Register
Claims
1. A computing device that performs calculations in communication between a terminal device and a network, wherein the calculations are performed using a given key and information relating to the privacy of the person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible.
2. The arithmetic device according to claim 1, wherein the calculation is used to derive AUTON or AUTOS.
3. The arithmetic device according to claim 1 or claim 2, wherein the information relating to the privacy of the person operating the terminal device is a sequence number.
4. The method for which the key cannot be erased and is reversible is an encryption process, according to the arithmetic apparatus of claim 1 or claim 2.
5. The arithmetic device according to claim 4, wherein the encryption process is Rocca-S.
6. The arithmetic unit according to claim 1 or claim 2, wherein the network is a function for user authentication.
7. A calculation method for performing calculations in communication between a terminal device and a network, wherein the calculation is performed using a given key and information relating to the privacy of the person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible.
8. A communication system comprising a terminal device and a network, wherein, in communication between the terminal device and the network, a given key and information relating to the privacy of the person operating the terminal device are used to perform calculations in a manner that makes it impossible to erase the key and is reversible.
9. A program that causes a computer to perform calculations in communication between a terminal device and a network, wherein the program causes a computer to perform calculation steps using a given key and information relating to the privacy of the person operating the terminal device, in a manner that makes it impossible to erase the key and is reversible.