Communication method and communication apparatus

WO2026200353A1PCT designated stage Publication Date: 2026-10-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/079534
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-25
Filing Date
2026-02-14
Publication Date
2026-10-01

Smart Images

  • Figure CN2026079534_01102026_PF_FP_ABST
    Figure CN2026079534_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and a communication apparatus. The method comprises: a first communication apparatus encrypts first data on the basis of N first keys to obtain a first ciphertext, wherein N is an integer greater than 1, and the N first keys correspond to a first security algorithm; the first communication apparatus may further separately encrypt the N first keys on the basis of a second security algorithm, to obtain N second keys, wherein a ciphertext encrypted by the second security algorithm supports being processed in an encrypted state; and the first communication apparatus sends the first ciphertext and the N second keys to a second communication apparatus. The second security algorithm may be understood as a homomorphic encryption algorithm. That is to say, in the technical solution, the first communication apparatus does not need to provide a homomorphically encrypted ciphertext to the second communication apparatus; instead, the second communication apparatus generates the homomorphically encrypted ciphertext by itself. Thus, data security of the first communication apparatus is improved while transmission overhead of the first communication apparatus is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and communication devices

[0001] This application claims priority to Chinese Patent Application No. 202510373011.2, filed on March 25, 2025, entitled "Communication Method and Communication Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communications, and more specifically, to a communication method and a communication device. Background Technology

[0003] Homomorphic encryption is a key technology in privacy computing, applicable to data transmission between clients and servers. For example, a client can homomorphically encrypt its original data and provide the encrypted ciphertext to the server. The server can then directly process the ciphertext, avoiding the exposure of the client's original data. This approach protects data privacy and improves data security while enabling efficient data utilization.

[0004] However, homomorphic encryption can lead to a surge in data volume, with the ciphertext potentially being dozens of times larger than the original data. Transmitting homomorphically encrypted ciphertext between the client and server results in significant data transmission overhead. Summary of the Invention

[0005] This application provides a communication method that aims to reduce data transmission overhead while ensuring data security.

[0006] Firstly, a communication method is provided. This method can be executed by a first communication device, by a component within the first communication device, or by a logic module or software capable of implementing all or part of the functions of the first communication device. The first communication device can be a client device, a terminal device, a consumer device, an artificial intelligence user (AI user) device, etc. The components within the first communication device can be a communication module, a processor, a chip, or a chip system, etc. The communication module within the first communication device can be a circuit or chip responsible for communication functions within the first communication device. This circuit or chip can be, for example, a modem chip (also known as a baseband chip), a system-on-a-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip. For ease of description, the following explanation uses the execution of the first communication device as an example.

[0007] The communication method includes: a first communication device encrypting first data based on N first keys to obtain first ciphertext. N is an integer greater than 1, and the N first keys correspond to a first security algorithm, or in other words, the N first keys are determined based on the first security algorithm. Additionally, the first communication device can also encrypt the N first keys separately based on a second security algorithm to obtain N second keys. The second security algorithm is characterized in that the ciphertext encrypted by the second security algorithm can be processed in its ciphertext state. This means that the ciphertext encrypted by the second security algorithm can be processed directly in its ciphertext state without needing to be decrypted. Therefore, the N second keys support decryption of the ciphertext obtained based on the first security algorithm in the ciphertext state corresponding to the second security algorithm. Further, the first communication device sends the aforementioned first ciphertext and N second keys to the second communication device.

[0008] In this embodiment of the application, the key or ciphertext in the ciphertext state corresponding to the second security algorithm indicates that the key or ciphertext has been encrypted using the second security algorithm and has not been decrypted using the second security algorithm; or, it can also indicate that the key or ciphertext needs to be decrypted using the decryption key corresponding to the second security algorithm to obtain the plaintext. The key or ciphertext in the ciphertext state corresponding to the second security algorithm can also be referred to as the key or ciphertext being in the ciphertext state corresponding to the second security algorithm.

[0009] Additionally, "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm" means that the key or ciphertext was not encrypted using the second security algorithm, or was previously encrypted using the second security algorithm and has already been decrypted using the second security algorithm. Here, "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm" can also be referred to as "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm", or "the key or ciphertext is not in the ciphertext state corresponding to the second security algorithm".

[0010] Similarly, the ciphertext state corresponding to the first security algorithm indicates that the key or ciphertext has been encrypted using the first security algorithm but has not been decrypted using the first security algorithm; or, it can also indicate that the key or ciphertext needs to be decrypted using the decryption key corresponding to the first security algorithm to obtain the plaintext. The ciphertext state corresponding to the first security algorithm can also be referred to as the key or ciphertext being in the ciphertext state corresponding to the first security algorithm.

[0011] In addition, the statement that the key or ciphertext is not in the ciphertext state corresponding to the first security algorithm means that the key or ciphertext was not encrypted based on the first security algorithm, or was previously encrypted based on the first security algorithm and has been decrypted based on the first security algorithm. The statement that the key or ciphertext is not in the ciphertext state corresponding to the first security algorithm can also be referred to as the plaintext state corresponding to the first security algorithm, or the statement that the key or ciphertext is not in the ciphertext state corresponding to the first security algorithm.

[0012] It should be understood that if the ciphertext is in the ciphertext state corresponding to the first security algorithm and in the plaintext state corresponding to the second security algorithm, then the aforementioned N first keys can be used to decrypt the ciphertext, and the result is in the plaintext state corresponding to the first security algorithm. If the ciphertext is in the ciphertext state corresponding to the first security algorithm and in the ciphertext state corresponding to the second security algorithm, then the N second keys obtained by encrypting the N first keys based on the second security algorithm can be used to decrypt the ciphertext, and the result is in the plaintext state corresponding to the first security algorithm, but still in the ciphertext state corresponding to the second security algorithm. Furthermore, during the decryption process, the N second keys remain in the ciphertext state corresponding to the second security algorithm.

[0013] Based on the above technical solution, the first communication device can encrypt the first data using N first keys to obtain the first ciphertext, and then provide the first ciphertext to the second communication device. Additionally, the first communication device can also provide N second keys to the device that decrypts the first ciphertext encrypted using the second security algorithm (hereinafter, the second communication device is used as an example), so that the second communication device can use the N second keys to decrypt the first ciphertext encrypted using the second security algorithm. The ciphertext encrypted using the second security algorithm can be processed in its ciphertext state. In other words, in this technical solution, the first communication device does not need to provide the homomorphically encrypted ciphertext to the second communication device; instead, the second communication device generates the homomorphically encrypted ciphertext itself for subsequent decryption, thereby reducing data transmission overhead while ensuring data security.

[0014] For example, the second security algorithm in this application can be understood as a homomorphic encryption algorithm.

[0015] In addition, the first communication device can provide N second keys to the second communication device, so that the second communication device can obtain the keys required for decryption before decrypting the first ciphertext encrypted based on the second security algorithm, without having to deduce the keys, thus reducing the complexity of the second communication device.

[0016] Furthermore, in the process of generating N second keys by the first communication device, the N second keys can be generated based on the second security algorithm and the N first keys. In the prior art, when a server decrypts the first ciphertext encrypted based on the second security algorithm, it needs to perform key expansion on the master key encrypted based on the second security algorithm to obtain the N second keys. This can be understood as the server needing to derive the round key based on the homomorphically encrypted master key in the prior art. However, in this application, the first communication device obtains N first keys by key expansion based on the master key in the plaintext state, and then obtains N second keys by encrypting based on the N first keys. It does not need to perform key expansion on the master key in the second security algorithm encryption state in the ciphertext state corresponding to the second security algorithm, thus reducing the complexity of obtaining the N second keys and helping to reduce the latency of the second communication device performing calculations and analysis.

[0017] In conjunction with the first aspect, in some implementations of the first aspect, the above-mentioned encryption of the N first keys based on the second security algorithm to obtain N second keys can also be: first, encrypting the N first keys based on the second security algorithm to obtain N third keys. Then, determining the N second keys based on the N third keys.

[0018] Based on the above technical solution, in the process of the first communication device determining N second keys, it can further process N third keys to obtain the required N second keys. These N third keys are obtained by encrypting N first keys using a second security algorithm. It should be understood that the key required for the decryption process of the second communication device is the N third keys. In this technical solution, the N second keys provided by the first communication device to the second communication device can be keys obtained through further processing of the N third keys. If the N second keys provided by the first communication device to the second communication device are keys obtained through further processing of the N third keys, then the second communication device can restore the N third keys based on the N second keys before performing the decryption operation. This key provision scheme, since it does not directly provide the N third keys to the second communication device but instead provides processed keys, can provide a certain degree of security for key transmission.

[0019] In conjunction with the first aspect, in some implementations of the first aspect, the aforementioned first ciphertext may include M block ciphertexts, where M is an integer greater than 1. The first communication device sends the first ciphertext and N second keys to the second communication device, which may be done by: first sending the first block ciphertext from the M block ciphertexts, then sequentially sending the N second keys based on the decryption process of the first block ciphertext by the second communication device, and after the first block ciphertext is decrypted, sequentially sending the block ciphertexts from the M block ciphertexts excluding the first block ciphertext.

[0020] Based on the above technical solution, the process of the first communication device providing N second keys to the second communication device can be achieved by providing the N second keys to the second communication device in stages. Under this technical solution, the first communication device does not need to provide all N second keys to the second communication device at once, but can provide the keys required by the second communication device sequentially based on the decryption progress of the second communication device, which can reduce the key transmission overhead to a certain extent. For example, in the event of a decryption error or an anomaly by the second communication device, subsequent keys do not need to be provided.

[0021] In conjunction with the first aspect, in some implementations of the first aspect, the first communication device can send N second keys to the second communication device when the first security algorithm is a non-shared security algorithm.

[0022] Based on the above technical solution, before the first communication device provides N second keys to the second communication device, it can determine whether the first security algorithm corresponding to the N first keys required to generate the N second keys is a shared security algorithm. If the first security algorithm is a shared security algorithm, the second communication device can determine the N first keys based on the first security algorithm, and then encrypt the N first keys respectively based on the second security algorithm to obtain the required N second keys, without the first communication device providing them to the second communication device. If the first security algorithm is determined to be a non-shared security algorithm, sending the N second keys to the second communication device can avoid unnecessary key transmission overhead to a certain extent.

[0023] In conjunction with the first aspect, in some implementations of the first aspect, the first communication device may provide N second keys to the second communication device through a first message, wherein the first message includes N second keys and N key identifiers, and the N key identifiers are used to identify the N second keys respectively.

[0024] Based on the above technical solution, the first communication device can also provide the second communication device with N identifiers of the second key, so that the second communication device can manage the keys based on the key identifiers, thereby improving key management performance. For example, after the second communication device obtains the identifiers of the N second keys, in subsequent scenarios where N second keys are needed, the first communication device can send the corresponding key identifiers to the second communication device.

[0025] In conjunction with the first aspect, in some implementations of the first aspect, the first communication device may provide a first ciphertext to the second communication device via a second message, the second message including the first ciphertext and an identifier of a first session, the first session being used to transmit at least one ciphertext, the first ciphertext being one of at least one ciphertext, wherein the identifier of the first session is associated with the aforementioned N second keys.

[0026] Based on the above technical solution, the first ciphertext provided by the first communication device to the second communication device can be one of at least one ciphertext associated with the first session. By carrying the identifier of the first session in the second message carrying the first ciphertext, the second communication device can determine that the first ciphertext is associated with the first session based on the first identifier. Furthermore, the identifier of the first session is associated with the aforementioned N second keys, thus the second communication device can perform subsequent decryption procedures based on the N second keys. In addition, since the first session is associated with at least one ciphertext, the N second keys can be used to perform subsequent decryption procedures for all ciphertexts associated with the first session, eliminating the need to provide a corresponding decryption key for each ciphertext. This reduces the overhead of key transmission in scenarios where a session is associated with multiple ciphertexts.

[0027] In conjunction with the first aspect, in some implementations of the first aspect, the aforementioned first session can be an AI service session.

[0028] Based on the above technical solution, the first session established between the first communication device and the second communication device can be an AI service session. This means the technical solution can be applied to AI scenarios, improving data security within those scenarios. Furthermore, this technical solution allows the introduction of homomorphic encryption algorithms into AI scenarios to homomorphically encrypt the data of the AI ​​client, enabling the data to be analyzed in a homomorphically encrypted state and protecting the privacy of the AI ​​client.

[0029] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the first communication device sending first indication information and / or second indication information to the second communication device, wherein the first indication information is used to indicate the length of the first key, and the second indication information is used to indicate the first security algorithm and / or the second security algorithm.

[0030] Based on the above technical solution, the first communication device can send information indicating the key length and information indicating the security algorithm to the second communication device, so that the second communication device can determine the key length and security algorithm type based on the relevant indication information, thereby improving the accuracy of the solution.

[0031] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: a first communication device receiving a first calculation result from a second communication device, the first calculation result being in an encrypted state corresponding to the second security algorithm. The first communication device decrypts the first calculation result based on the decryption key corresponding to the second security algorithm to obtain a second calculation result.

[0032] Based on the above technical solution, the second communication device can provide the first communication device with the first calculation result after homomorphic computation, enabling the first communication device to obtain the analysis results related to the first data. Furthermore, the first calculation result is determined based on homomorphic computation of the second ciphertext using the computation key in a ciphertext state. This means that the second communication device does not actually obtain the plaintext of the first data during data analysis, ensuring the data security of the first communication device. Moreover, the fact that the data of the first communication device can be analyzed in a homomorphic ciphertext state enhances the data privacy protection of the first communication device.

[0033] In conjunction with the first aspect, in some implementations of the first aspect, the aforementioned first communication device may be an artificial intelligence user (AI) device.

[0034] Secondly, a communication method is provided. This method can be executed by a second communication device, by a component within the second communication device, or by a logic module or software capable of implementing all or part of the functions of the second communication device. The second communication device can be a server, producer equipment, network equipment, or an artificial intelligence agent (AI agent) device, etc. Components within the second communication device can be modules, processors, chips, or chip systems, etc. The communication module within the second communication device can be a circuit or chip responsible for communication functions. This circuit or chip can be a modem chip, also known as a baseband chip, or a SoC chip or SIP chip containing a modem core. For ease of description, the following explanation uses the execution by a second communication device as an example.

[0035] The communication method includes: a second communication device acquiring a third ciphertext, wherein the third ciphertext is obtained by encrypting a first ciphertext based on a second security algorithm, and the first ciphertext is obtained by encrypting first data based on N first keys corresponding to the first security algorithm, where N is an integer greater than 1; receiving N second keys, wherein the N second keys are obtained by encrypting the N first keys respectively based on the second security algorithm; and decrypting the third ciphertext according to the N second keys to obtain a second ciphertext, wherein the second ciphertext is in the ciphertext state corresponding to the second security algorithm. During the decryption process, the N second keys and the third ciphertext are in the ciphertext state corresponding to the second security algorithm.

[0036] For example, the second ciphertext in the ciphertext state corresponding to the second security algorithm can be: the second ciphertext is the first data encrypted based on the encryption key corresponding to the second security algorithm.

[0037] Based on the above technical solution, the N second keys required for the second communication device to decrypt the third ciphertext are received from other devices, eliminating the need to generate the N second keys required for decryption. In existing technologies, a server decrypting the first ciphertext (i.e., the third ciphertext) encrypted using the second security algorithm needs to perform key expansion on the master key encrypted using the second security algorithm to obtain the N second keys. This can be understood as the server needing to derive the round key based on the homomorphic encryption master key. However, in this application, the second communication device only needs to receive the required N keys, without needing to perform key expansion on the master key encrypted using the second security algorithm. This reduces the complexity of the second communication device obtaining the N second keys, thereby reducing the latency of the second communication device performing computational analysis.

[0038] In conjunction with the second aspect, in some implementations of the second aspect, the first ciphertext comprises M block ciphertexts, where M is an integer greater than 1. The method further includes: a second communication device receiving a first block ciphertext from the M block ciphertexts received from a first communication device. The aforementioned receiving of N second keys includes: the second communication device sequentially receiving N second keys from the first communication device; after the first block ciphertext is decrypted, the method further includes: the second communication device sending a first response message to the first communication device, the first response message indicating that the first block ciphertext has been decrypted, and sequentially receiving the block ciphertexts from the M block ciphertexts excluding the first block ciphertext.

[0039] Based on the above technical solution, the process of the first communication device providing N second keys to the second communication device can be achieved by providing the N second keys to the second communication device in stages. Under this technical solution, the first communication device does not need to provide all N second keys to the second communication device at once, but can provide the keys required by the second communication device sequentially based on the decryption progress of the second communication device, which can reduce the key transmission overhead to a certain extent. For example, in the event of a decryption error or an anomaly by the second communication device, subsequent keys do not need to be provided.

[0040] In conjunction with the second aspect, in some implementations of the second aspect, receiving N second keys includes: receiving a first message, the first message including the N second keys and N key identifiers, the N key identifiers being used to identify the N second keys respectively.

[0041] Based on the above technical solution, the first communication device can also provide the second communication device with N identifiers for the second keys, enabling the second communication device to manage the keys based on the key identifiers and improving key management performance. For example, after the second communication device determines the identifiers for the N second keys, in subsequent scenarios where N second keys are needed, the first communication device can simply send the corresponding key identifiers to the second communication device.

[0042] In conjunction with the second aspect, in some implementations of the second aspect, obtaining the third ciphertext includes: receiving the first ciphertext; encrypting the first ciphertext based on the second security algorithm to obtain the third ciphertext. In conjunction with the second aspect, in some implementations of the second aspect, receiving the first ciphertext includes: receiving a second message, the second message including the first ciphertext and an identifier of a first session, the first session being used to transmit at least one ciphertext, the first ciphertext being one of the at least one ciphertext, and the method further includes: determining the N second keys based on the identifier of the first session.

[0043] Based on the above technical solution, the first ciphertext provided by the first communication device to the second communication device can be one of at least one ciphertext associated with the first session. By carrying the identifier of the first session in the second message carrying the first ciphertext, the second communication device can determine that the first ciphertext is associated with the first session based on the first identifier. Furthermore, the identifier of the first session is associated with the aforementioned N second keys, thus the second communication device can perform subsequent decryption procedures based on the N second keys. In addition, since the first session is associated with at least one ciphertext, the N second keys can be used to perform subsequent decryption procedures for all ciphertexts associated with the first session, eliminating the need to provide a corresponding decryption key for each ciphertext. This reduces the overhead of key transmission in scenarios where a session is associated with multiple ciphertexts.

[0044] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving a third message, the third message being used to request the establishment of the first session; in response to the third message, allocating an identifier for the first session; sending the identifier of the first session, wherein receiving N second keys includes: receiving the N second keys and the identifier of the first session, the identifier of the first session being associated with the N second keys.

[0045] In conjunction with the second aspect, in some implementations of the second aspect, the first session includes an artificial intelligence (AI) service session.

[0046] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving a fourth message, the fourth message including an identifier of a first communication device; obtaining subscription information of the first communication device based on the identifier of the first communication device; and determining, based on the subscription information, to provide computing services based on the second security algorithm to the first communication device.

[0047] In conjunction with the second aspect, in some implementations of the second aspect, determining to provide the first communication device with computing services based on the second security algorithm based on the subscription information includes: determining a security service policy for the first communication device based on the subscription information, wherein the security service policy indicates that computing services based on the second security algorithm are permitted for the first communication device; and determining to provide computing services based on the second security algorithm for the first communication device according to the security service policy. Wherein, the subscription information or the security service policy indicates that the first communication device has subscribed to computing services based on the second security algorithm.

[0048] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving first indication information and / or second indication information, wherein the first indication information is used to indicate the length of the first key, and the second indication information is used to indicate the first security algorithm and / or the second security algorithm.

[0049] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: performing calculations on the second ciphertext based on the calculation key corresponding to the second security algorithm to obtain a first calculation result; and sending the first calculation result.

[0050] In conjunction with the second aspect, in some implementations of the second aspect, the aforementioned second communication device includes an artificial intelligence agent device.

[0051] The beneficial effects of the second aspect and its possible implementation methods can be found in the description of the first aspect, and will not be repeated here.

[0052] Thirdly, a communication device is provided. This communication device is used to execute the methods described in the first aspect and any implementation thereof. For example, the communication device includes modules, units, or means corresponding to the operations involved in the first aspect. These modules, units, or means can be implemented in software, hardware, or a combination of software and hardware.

[0053] In one possible design, the communication device includes: a processing unit for encrypting first data based on N first keys to obtain first ciphertext; the processing unit is further configured to encrypt each of the N first keys based on a second security algorithm to obtain N second keys; and a communication unit for sending the first ciphertext and the N second keys to a second communication device.

[0054] The communication unit can perform the receiving and transmitting processes described in the first aspect above, and the processing unit can perform other processes described in the first aspect above besides receiving and transmitting.

[0055] The aforementioned communication device may be a first communication device, or a communication module in the first communication device, or a chip in the first communication device that is responsible for communication functions, such as a modem chip (also known as a baseband chip) or a SoC or SIP chip containing a modem module, or a logic node, logic module or software that can realize all or part of the functions of the first communication device.

[0056] Fourthly, a communication device is provided. This communication device is used to execute the methods described in the second aspect and any implementation thereof. For example, the communication device includes modules, units, or means corresponding to the operations involved in the second aspect. These modules, units, or means can be implemented in software, hardware, or a combination of software and hardware.

[0057] In one possible design, the communication device includes: a communication unit for acquiring third ciphertext, which is obtained by encrypting first ciphertext using a second security algorithm. The first ciphertext is obtained by encrypting first data using N first keys corresponding to the first security algorithm, where N is an integer greater than 1. The ciphertext encrypted using the second security algorithm supports processing in ciphertext state. The communication unit is also configured to receive N second keys, which are obtained by encrypting the N first keys respectively using the second security algorithm. A processing unit is configured to decrypt the third ciphertext using the N second keys to obtain second ciphertext, which is in ciphertext state corresponding to the second security algorithm.

[0058] The communication unit can perform the receiving and transmitting processes described in the second aspect above, and the processing unit can perform other processes described in the second aspect above besides receiving and transmitting.

[0059] The aforementioned communication device may be a second communication device, or a communication module in a second communication device, or a chip in a second communication device that is responsible for communication functions, such as a modem chip (also known as a baseband chip) or a SoC or SIP chip containing a modem module, or a logic node, logic module or software that can implement all or part of the second communication device.

[0060] Fifthly, a communication device is provided. The communication device includes at least one processor. The at least one processor is capable of executing a computer program or instructions, which, when executed, cause the communication device to implement the methods of any one of the first and second aspects and any implementation thereof.

[0061] In one possible design, the communication device may further include at least one interface circuit. This interface circuit is used to implement communication functions within the communication device and / or communication functions between the communication device and other devices or components.

[0062] In one possible design, the communication device may further include at least one interface circuit and / or at least one memory. The at least one processor is coupled to the at least one memory. The at least one memory is used to store part or all of the necessary computer programs or instructions for implementing the functions involved in either the first or second aspect described above and their respective implementations. The interface circuit is used to implement the communication functions within the communication device and / or the communication functions between the communication device and other devices or components.

[0063] In one possible design, the at least one processor is used to communicate with other devices or components via at least one interface circuit.

[0064] The aforementioned communication device may be a first communication device, or a communication module in the first communication device, or a chip in the first communication device responsible for communication functions, or a logic node, logic module, or software that can realize all or part of the functions of the first communication device.

[0065] The aforementioned communication device may be a second communication device, or a communication module in a second communication device, or a chip in a second communication device responsible for communication functions, or a logic node, logic module, or software that can realize all or part of the functions of the second communication device.

[0066] Sixthly, a communication system is provided. This communication system includes the communication devices described in the third and / or fourth aspects.

[0067] In a seventh aspect, a chip or chip system is provided. The chip or chip system includes at least one processing circuitry for executing a computer program or instructions, causing the chip or chip system to perform the methods described in the first and second aspects and any possible implementation thereof.

[0068] The chip or chip system may include output circuits or interfaces for transmitting information or data, and input circuits or interfaces for receiving information or data.

[0069] Eighthly, a computer-readable storage medium is provided. This computer-readable storage medium stores computer program code or instructions, which, when executed by a processor, implement the methods of the first and second aspects and any possible implementation thereof.

[0070] Ninthly, a computer program product is provided. The computer program product includes: computer program code or instructions, wherein when a processor executes the computer program code or instructions, the method in any of the possible implementations of the first and second aspects described above is implemented.

[0071] In a tenth aspect, a computer program is provided. When the computer program is run, it causes the methods of the first and second aspects and any possible implementation thereof to be implemented.

[0072] It should be understood that the beneficial effects of the third to tenth aspects mentioned above can be referenced from the first aspect mentioned above and any possible implementation thereof, which will not be elaborated here. Attached Figure Description

[0073] Figure 1 is a schematic diagram of the network architecture 100 provided in this application.

[0074] Figure 2 is a schematic diagram of a NAS security setup process.

[0075] Figure 3 is a schematic diagram of a data processing process based on homomorphic encryption technology.

[0076] Figure 4 is a schematic diagram of homomorphic key generation.

[0077] Figure 5 is a schematic diagram of a homomorphic encryption process.

[0078] Figure 6 is a schematic diagram of a homomorphic decryption process.

[0079] Figure 7 is a schematic diagram of a homomorphic computation process.

[0080] Figure 8 is a schematic diagram of a homomorphic encryption scheme.

[0081] Figure 9 is a schematic diagram of the encryption process.

[0082] Figure 10 is a schematic flowchart of a communication method provided in this application.

[0083] Figure 11 is a schematic diagram of a key provided in this application.

[0084] Figure 12 is a schematic block diagram of the communication device 10 provided in an embodiment of this application.

[0085] Figure 13 is a schematic diagram of another communication device 20 provided in an embodiment of this application. Detailed Implementation

[0086] To facilitate understanding of the embodiments of this application, the following points will be explained first.

[0087] First, in this application, "for indicating" can include both direct and indirect indication. When describing an indication information as indicating A, it can include whether the indication information directly indicates A or indirectly indicates A, but does not necessarily mean that the indication information carries A.

[0088] The information indicated by the instruction is called the information to be instructed. In the specific implementation process, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also be indirectly indicated by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be indicated, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. At the same time, common parts of various pieces of information can be identified and indicated uniformly to reduce the instruction overhead caused by individually indicating the same information.

[0089] Second, in this application, "at least one" refers to one or more, and "more than one" refers to two or more (including two). Furthermore, in the embodiments of this application, "first," "second," and various numerical designations (e.g., "#1," "#2," etc.) are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The sequence numbers of the processes below do not imply an order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. It should be understood that the objects described in this way can be interchanged where appropriate to describe solutions other than those in the embodiments of this application. Moreover, in the embodiments of this application, terms such as "S1010" are merely identifiers for descriptive convenience and do not limit the order of execution steps.

[0090] Third, in the embodiments of this application, the words "exemplary" or "for example" are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design that is described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design options. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0091] Fourth, the term "storage" in the embodiments of this application can refer to storage in one or more memories. These memories can be separate installations or integrated into an encoder, decoder, processor, or communication device. Alternatively, some memories can be separately installed, while others can be integrated into the decoder, processor, or communication device. The type of memory can be any form of storage medium, and this application does not limit this.

[0092] Fifth, in the implementation of this application, "protocol" may refer to standard protocols in the field of communications, such as the NR protocol and related protocols applied in future communication systems, and this application does not limit it.

[0093] Sixth, in the embodiments of this application, the terms "of", "corresponding (relevant)", "corresponding", and "associate" can sometimes be used interchangeably. It should be noted that when their differences are not emphasized, their intended meanings are consistent.

[0094] Seventh, in the embodiments of this application, "under the circumstances", "when", and "if" can sometimes be used interchangeably. It should be noted that when the distinction is not emphasized, their intended meanings are consistent.

[0095] Eighth, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0096] Ninth, in this article, "message", "information", or "information element (IE)" can be used interchangeably. There are no restrictions on the name of the message or information, as long as it can achieve the corresponding function.

[0097] Tenth, in this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, and "send information" can include direct transmission or indirect transmission through other units or modules. "Receive information from YY" can be understood as the source of the information being YY, and "receive information" can include direct reception from YY or indirect reception from YY through other units or modules. Besides air interface transmission or reception signals implemented at the system level, such as the first or second communication device, "send" can also be understood as the "output" of a chip interface, and "receive" can also be understood as the "input" of a chip interface. For example, a modem or system-on-a-chip (SoC) chip or system-in-package (SIP) chip transmits or receives signals. "Send" or "receive" can also be performed through device components, for example, by using buses, traces, or interfaces to transmit or receive signals through several parts, modules, or chips of a device.

[0098] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0099] The technical solutions of this application embodiment can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, 5th Generation (5G) systems, or New Radio (NR) systems and future communication systems, vehicle-to-X (V2X) communication, where V2X can include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc., Long Term Evolution-Vehicle (LTE-V) communication, vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), Long Term Evolution-Machine (LTE-M) communication, machine-to-machine (M2M) communication, and wireless local area networks (WLANs). (network, WLAN, etc.)

[0100] In addition, the technical solution of this application can be applied to satellite communication systems, high altitude platform station (HAPS) communication, non-terrestrial network (NTN) systems such as UAVs, integrated communication and navigation (ICAN) systems, global navigation satellite systems (GNSS), and ultra-dense low-Earth orbit satellite communication systems.

[0101] For ease of description, this application will use a public land mobile network (PLMN) or a 5G network as examples in its embodiments.

[0102] Figure 1 is a schematic diagram of the communication system applicable to this application. Taking the 5G network architecture based on a service-oriented architecture in a non-roaming scenario as defined during the 3rd Generation Partnership Project (3GPP) standardization process as an example, as shown in the figure, this network architecture can include three parts: the terminal equipment part, the data network (DN), and the operator network PLMN part. The functions of the network elements in each part are briefly explained below.

[0103] The terminal equipment section may include terminal equipment 110. Terminal equipment can be a device or module that is connected to the aforementioned communication system and has corresponding communication functions. Terminal equipment may also be referred to as user equipment (UE), terminal, user device, access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal unit, terminal station, terminal device, wireless communication equipment, user agent, or user device. The terminal typically contains a communication module, circuit, or chip that performs the corresponding communication functions. The terminal may also be configured with program instructions for performing the corresponding communication functions.

[0104] For example, the terminal in this application embodiment can be a mobile phone, a personal digital assistant (PDA) computer, a laptop computer, a tablet computer, a drone, a computer with wireless transceiver capabilities, a machine-type communication (MTC) terminal, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a point-of-sale (POS) machine, customer-premises equipment (CPE), a light user equipment (UE), a reduced capability UE (REDCAP UE), a wearable device (e.g., a smartwatch, smart bracelet, pedometer, smart glasses), an Internet of Things (IoT) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home. Wireless terminals in the home (such as game consoles, smart TVs, smart speakers, smart refrigerators, and fitness equipment), transportation vehicles with wireless communication capabilities, communication modules, roadside units (RSUs) with terminal functions, and flying equipment (such as smart robots, hot air balloons, drones, and airplanes). Terminal equipment can also be vehicle devices, such as complete vehicle devices, vehicle-mounted modules, vehicle-mounted chips, on-board units (OBUs), or telematics boxes (T-BOXs).

[0105] For example, the terminal in this embodiment can also be a client device, an artificial intelligence user (AI user) device, or other similar devices. For instance, the terminal can be a consumer of a network element, or a client of a service application (APP). Further examples will not be provided here.

[0106] The PLMN portion of the operator's network may include, but is not limited to, RAN 120 and the core network (CN) portion.

[0107] RAN 120 is the implementation system between service nodes and terminal equipment 110 in the operator network. For terminal equipment 110 to access the operator network, it first goes through RAN 120, and then can connect to service nodes in the operator network via RAN 120. In this application, RAN 120 may include one or more access network devices.

[0108] Access network equipment can be a network-side device with wireless transceiver capabilities. It can be a device within a radio access network (RAN) that provides wireless communication functionality to terminal devices, referred to as RAN equipment. RAN can be a cellular system related to the 3rd Generation Partnership Project (3GPP), such as a 5G mobile communication system, or a future-oriented evolution system (such as a next-generation mobile communication system). RAN can also be an open radio access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. For example, this access network equipment can be a base station, an evolved NodeB (eNodeB), a next-generation NodeB (gNB) in a 5G mobile communication system, a 3GPP subsequent evolution base station, a transmission reception point (TRP), an access node, a wireless relay node, or a wireless backhaul node in a WiFi system. In communication systems employing different radio access technologies (RATs), the names of devices with base station functionality may differ. For example, in an LTE system, it may be called an eNB or eNodeB, and in a 5G or NR system, it may be called a gNB. This application does not limit the specific name of the base station. Access network equipment may include one or more co-located or non-co-located transmit / receive points. Furthermore, access network equipment may include at least one of the following: one or more central units (CU), one or more distributed units (DU), and one or more radio units (RU). In different systems, CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art will understand their meaning. For example, in an open RAN (ORAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU (open DU), CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application may be implemented through software modules, hardware modules, or a combination of software and hardware modules.For example, the functionality of a CU can be implemented by one entity or different entities. For instance, the CU's functionality can be further divided, separating the control plane and user plane and implementing them through different entities: a control plane CU entity (i.e., the CU-CP entity) and a user plane CU entity (i.e., the CU-UP entity). The CU-CP and CU-UP entities can be coupled with a DU to jointly complete the access network device's functionality. For example, the CU is responsible for handling non-real-time protocols and services, implementing the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers. The DU is responsible for handling physical layer protocols and real-time services, implementing the functions of the radio link control (RLC), medium access control (MAC), and physical (PHY) layers. In this way, some functions of the wireless access network device can be implemented through multiple network function entities. These network function entities can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The access network device can also include an active antenna unit (AAU). The AAU implements some physical layer processing functions, radio frequency processing, and related functions of the active antenna. Since RRC layer information ultimately becomes PHY layer information, or is derived from PHY layer information, in this architecture, higher-layer signaling, such as RRC layer signaling, can also be considered as being sent by the DU, or by the DU+AAU. It is understood that access network equipment can be one or more of the following: CU nodes, DU nodes, and AAU nodes. Furthermore, the CU can be classified as an access network device in the radio access network (RAN), or as an access network device in the core network (CN); this application does not limit this. For example, in V2X technology, access network equipment can be a roadside unit (RSU). Multiple access network devices in a communication system can be base stations of the same type or different types. Base stations can communicate with terminal devices directly, or they can communicate with terminal devices through relay stations. In this embodiment, the device for implementing the access network device function can be the access network device itself, or it can be a device that supports the access network device in implementing the function, such as a chip system or a combination of devices or components that can implement the access network device function. This device can be installed in the access network device. In this embodiment, the chip system can be composed of chips, or it can include chips and other discrete devices.

[0109] Additionally, as an example, the access network equipment in this application may also include service management and orchestration (SMO), wherein the SMO includes a RAN intelligent controller (RIC). Optionally, the RIC includes two types: a non-real-time radio intelligent controller (non-RT-RIC) and a near-real-time radio intelligent controller (near-RT-RIC).

[0110] The non-RT-RIC is deployed within the SMO, and its main responsibilities are: to provide policy, machine language (ML) model management, and a large amount of information to achieve intelligent RAN optimization; and to enable rApp functionality. rApp can collect information and take actions through the A1, O1, O2, and open fronthaul management plane (Open FH M-Plane) interfaces to achieve RAN optimization. rApp is a portable, functional application.

[0111] The near-RT-RIC is deployed within the SMO, and its main responsibility is to provide near real-time radio resource control and optimization to the base station based on data collected by the E2 nodes. The CN part may include, but is not limited to, the following network functions (NFs): User plane function (UPF)130, Network exposure function (NEF)131, Network function repository function (NRF)132, Policy control function (PCF)133, Unified data management (UDM)134, Unified data repository (UDR)135, Network data analytics function (NWDAF)136, Authentication server function (AUSF)137, AMF138, and Session management function (SMF)139.

[0112] Optionally, the CN part may also include an application function (AF) 141 and a sensing function (SF) 142.

[0113] Data network DN 140, also known as packet data network (PDN), is typically a network located outside the operator's network, such as a third-party network. However, in some implementations, the DN can also be deployed by the operator, meaning the DN is part of a PLMN. This application does not restrict whether the DN belongs to a PLMN. An operator's PLMN can connect to multiple data networks DN 140. Various services can be deployed on the data network DN 140, providing data and / or voice services to terminal devices 110. For example, data network DN 140 can be a private network of a smart factory. Sensors installed in the workshop of the smart factory can be terminal devices 110. A control server for the sensors is deployed in the data network DN 140, providing services to the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions. As another example, data network DN 140 can be an internal office network of a company. The mobile phones or computers of the company's employees can be terminal devices 110, and the employees' mobile phones or computers can access information and data resources on the company's internal office network. Terminal device 110 can establish a connection with the operator network through an interface (such as N1) provided by the operator network and use data and / or voice services provided by the operator network. Terminal device 110 can also access data network DN 140 through the operator network and use operator services deployed on data network DN 140, and / or services provided by third parties.

[0114] The following is a brief explanation of the NF functions included in CN.

[0115] 1. PCF 133 is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provide policy rules and subscription information related to policy decisions to other control functions.

[0116] 2. UDM 134 is a control plane function provided by the operator, responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribed users in the operator's network. The SUPI undergoes confidentiality protection during transmission; this confidential SUPI is called the subscription concealed identifier (SUCI). The information stored in UDM 134 can be used for authentication and authorization of terminal device 110 when accessing the operator's network. Specifically, the subscribed users of the aforementioned operator's network can be users of services provided by the operator's network, such as users using a subscriber identity module (SIM) card from operator A or operator B. The credentials of the subscribed users can be a long-term key stored in the SIM card or a small file containing information related to SIM card encryption, used for authentication and / or authorization. It should be noted that, for the sake of convenience, the permanent identifier, trust certificate, security context, authentication data (cookie), and token are not distinguished or limited in this application embodiment for the purpose of description.

[0117] 3. UDR 135 is a control plane function provided by the operator, which provides UDM with the ability to store and retrieve subscription data, PCF with the ability to store and retrieve policy data, and stores and retrieves user NF group identifier (group ID) information, etc.

[0118] 4. NWDAF 136 is a control plane function provided by the operator. Its main function is to collect data from NF, external application functions (AF), and operation, administration and maintenance (OAM) systems, and to provide NWDAF service registration, data access, and analysis data to NF and AF. In this application, NWDAF is mainly responsible for security-related data analysis. Therefore, in this application, NWDAF can also be understood as a network element with security analysis capabilities. The term NWDAF is just an example; other network element names may be used subsequently, and this application does not limit this.

[0119] 5. AUSF 137 is a control plane function provided by the operator, typically used for Level 1 authentication, i.e., authentication between terminal device 110 (the subscriber) and the operator's network. After receiving an authentication request from the subscriber, AUSF 137 can authenticate and / or authorize the subscriber using the authentication and / or authorization information stored in UDM 134, or generate the subscriber's authentication and / or authorization information using UDM 134. AUSF 137 can then send the authentication and / or authorization information back to the subscriber.

[0120] 6. AMF 138 is a control plane network function provided by the operator's network, which is responsible for access control and mobility management of terminal equipment 110 accessing the operator's network. This includes functions such as mobility state management, allocation of temporary user identity identifiers, authentication and authorization of users.

[0121] 7. SF 142 is used for network elements that process and compute sensed data. It can be any network element capable of computation, such as network data analysis function network elements, analysis logical function network elements (AnLF), model trains logical function network elements (MTLF) and other artificial intelligence (AI) function network elements, or location management function (LMF), as well as any future network elements with computational tasks.

[0122] In this application, the sensing control function (SF) can be deployed in the core network or in a non-core network, without limitation. The SF can utilize access network equipment and / or terminal equipment for sensing. The SF can be co-located with other network elements, or its functions can be implemented by other network elements, or the SF can be configured independently; this application does not limit this. Optionally, the SF can also be called a sensing control function (SCF) or other possible names.

[0123] For example, the SF can transmit sensing control signaling with access network equipment and / or terminal equipment through access and mobility management function network elements. The sensing measurement data acquired by the access network equipment and / or terminal equipment can be transmitted to the SF via the control plane or user plane. The user plane can be forwarded through user plane function network elements or directly transmitted to the SF. For example, the aforementioned communication interfaces (such as N1, N2, N5, or N8, etc.) can support the transmission of sensing service-related information, such as authentication information, sensing service type, sensing service quality requirements, sensing measurement data, or sensing information.

[0124] It is understandable that the aforementioned network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualization functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented in hardware or software.

[0125] In Figure 1, Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, Nran, N1, N2, N3, N4, and N6 are interface sequence numbers. For example, the meanings of these interface sequence numbers can be found in the 3GPP standard protocols, and this application does not limit the meaning of these interface sequence numbers. It should be noted that the interface names between the various network functions in the figure are merely examples; in specific implementations, the interface names of this system architecture may be other names, and this application does not limit them. Furthermore, the names of the messages (or signaling) transmitted between the various network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.

[0126] For ease of explanation, network functions (such as NEF 131…SMF139) are collectively referred to as NFs in this application embodiment. That is, any NF described below in this application embodiment can be replaced by any network function. In addition, Figure 1 only schematically illustrates some network functions, and the NFs described below are not limited to the network functions shown in Figure 1.

[0127] It should be understood that the network architecture described above for the embodiments of this application is only a network architecture described from the perspective of service-oriented architecture. The network architecture applicable to the embodiments of this application is not limited to this, and any network architecture that can realize the functions of the above-described network elements is applicable to the embodiments of this application. For example, at least one of the network elements, access network devices, or terminal devices in this application can be deployed in NTN.

[0128] It should also be understood that AMF, SMF, UPF, NEF, AUSF, NRF, PCF, UDM, and SF shown in the figure can be understood as network elements in the core network used to implement different functions, such as network slices that can be combined as needed. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements. In addition, the network architecture shown in Figure 1 may also include other network elements, such as sensing function network elements, artificial intelligence logic function (e.g., model training logic function, analysis logic function) network elements, etc.

[0129] It should also be understood that the above naming is defined solely for the purpose of distinguishing different functions and should not constitute any limitation on this application. This application does not preclude the possibility of using other naming conventions in 5G networks and other future networks. For example, in future communication networks, some or all of the above-mentioned network elements may use the terminology from 5G, or they may use other names, etc.

[0130] It should be noted that Figure 1 above is merely an illustrative example illustrating the scenarios in which the embodiments of this application can be applied, and does not constitute any limitation on the scope of protection of this application. The embodiments provided by this application can also be applied to other communication scenarios. For example, the SF network element mentioned above can also be other computing network elements used to process data provided by the terminal. For another example, if the terminal is a client, the client can transmit information with the server; this scenario is not shown in Figure 1. For yet another example, if the terminal is an AI user, the AI ​​user can transmit information with an artificial intelligence agent (AI agent) device; this scenario is not shown in Figure 1. Further examples will not be provided here.

[0131] To facilitate understanding of the embodiments of this application, some basic concepts involved in this application are briefly explained. It should be understood that the basic concepts introduced below are illustrated using the basic concepts specified in the NR protocol as examples, but do not limit the embodiments of this application to be applied only to NR systems. Therefore, the standard names that appear when describing using an NR system as an example are functional descriptions, and the specific names are not limited, but only indicate the function of the device, which can be extended to other future systems.

[0132] 1. Privacy computation (or privacy computing): refers to a set of technologies that enable data analysis and computation while protecting the data itself from public disclosure, achieving the goal of making the data "usable but not visible"; and realizing the transformation and release of data value while fully protecting data and privacy security.

[0133] 2. Homomorphic Encryption: An important technique in privacy computing, homomorphic encryption encrypts the original data to obtain ciphertext, which can then be directly used for computation and analysis, preventing the original data from being exposed. The data before and after homomorphic encryption has the same computational properties, meaning both are homomorphic.

[0134] 3. Non-access stratum messages: These refer to messages sent by a terminal device to subsequent nodes through a wireless access node. This includes messages sent from the terminal device to the core network via the access network equipment, or messages sent from the DU to the CU via the DU. Because the access node does not process these messages, they are called non-access stratum messages. For ease of description, this application refers to all messages not processed by the access node as non-access stratum (NAS) messages. However, it should be understood that the name of the messages is not limited in this application, and messages not processed by the access node may have other names (e.g., other possible names defined in future communication protocols).

[0135] 4. NAS Security Setup: To facilitate understanding, the NAS security setup process defined by the existing protocol is explained in conjunction with Figure 2.

[0136] Figure 2 is a schematic diagram of a NAS security setup process. As shown in Figure 2, NAS security setup includes the following steps:

[0137] Step 1: The UE sends an initial NAS message to the access and mobility management function network element.

[0138] For example, if the UE does not have a NAS security context, the initial NAS message should only contain plaintext information elements (IEs), that is, the initial NAS message includes the subscription identifier (e.g., SUCI or Globally Unique Temporary Identity (GUTI)), UE security capabilities, ngKSI, etc.

[0139] For example, if the UE has a NAS security context, the initial NAS message sent should include the aforementioned plaintext information elements, as well as the complete initial NAS message encrypted in an encrypted NAS container. If the initial NAS message is protected and the access and mobility management function (AMF) network element has the same security context, steps 2 to 4 below can be omitted, and in this case, the AMF network element should use the complete initial NAS message in the NAS container as the message to respond to.

[0140] Step 2: If the Access and Mobility Management Function (AMF) network element cannot obtain the NAS security context locally or in the last visited AMF, or if the AMF fails to perform an integrity check on the received initial NAS message, the AMF should initiate an authentication process with the UE (e.g., step 2b shown in Figure 2). This application does not limit the specific authentication process and will not elaborate further here.

[0141] For example, if the Access and Mobility Management Function (AMF) element obtains the old NAS security context from the last AMF element accessed by the UE (e.g., step 2a shown in Figure 2), and the AMF can decipher the NAS container with the same security context and obtain the initial NAS message, then steps 2b to 4 can be omitted. If the AMF element obtains the new K_AMF from the last AMF element accessed (receiving keyAmfChangeInd), then step 2b can be omitted.

[0142] Step 3: If UE authentication is successful, the access and mobility management function network element should send a NAS security mode command message (NAS SMC).

[0143] If the initial NAS message is protected but fails the integrity check (e.g., due to a MAC failure or the access and mobility management function (AM) element being unable to find the security context to use), or the AM element is unable to decrypt the complete initial NAS message in the NAS container (e.g., due to receiving "keyAmfChangeInd" from the last accessed AM element), then the AM element should include a flag in the NAS security mode command message requesting the UE to send the complete initial NAS message in the NAS security mode complete message.

[0144] Step 4: The UE should send a NAS secure mode completion message to the Access and Mobility Management Function (AMS) network element in response to the NAS secure mode command message. The NAS secure mode completion message should be encrypted and its integrity protected. Furthermore, if the AMS network element requested or the UE sent an unprotected initial NAS message, the NAS secure mode completion message should include the complete initial NAS message from the NAS container. The AMS network element should use the complete initial NAS message from the NAS container as the message to respond to.

[0145] Step 5: The Access and Mobility Management (AMS) network element should send a response to the initial NAS message. This message should be encrypted and its integrity protected.

[0146] 5. Homomorphic Encryption and Privacy Computation: Data is one of the five major factors of production in the digital society. With the convergence of communication and sensing, sensing, as an inherent capability of future communication networks, provides a wealth of data to intelligent networks by sensing the network's own state, surrounding environment, and user / device behavior. From the perspective of data value mining, the network is both a producer and provider of data, offering trusted data services to various intelligent applications, and a consumer of network data, improving network performance and operational efficiency through data-driven intelligent applications.

[0147] Homomorphic encryption (HE) aims to perform computational processing on ciphertext data without exposing the plaintext data. It is a technology that enables data value mining while providing privacy protection.

[0148] Homomorphic encryption is based on basic encryption, but adds the ability to perform homomorphic computations on ciphertext. It allows computations to be performed directly on the encrypted ciphertext, and the result obtained after decrypting the ciphertext computation is consistent with the result obtained on the plaintext.

[0149] Figure 3 is a schematic diagram of a data processing procedure based on homomorphic encryption technology. As shown in Figure 3, plaintext data m is homomorphically encrypted to obtain ciphertext data c = E. pk (m), and this encrypted data is computed using homomorphic computation C. f Afterwards, the encrypted result was obtained. The result obtained by homomorphic decryption of the ciphertext is the same as the plaintext result f(m) obtained by calculating m using the plaintext calculation function f.

[0150] This application does not impose any restrictions on the encryption key used in the homomorphic encryption process. For example, homomorphic encryption can be fully homomorphic encryption (FHE), asymmetric encryption or symmetric encryption, as long as the ciphertext has a certain algebraic structure; or in other words, the ciphertext has homomorphic properties.

[0151] 6. Homomorphic Encryption Process: This includes homomorphic key generation (HE.Keygen), homomorphic encryption (HE.Enc), homomorphic decryption (HE.Dec), and homomorphic evaluation (HE.Eval). Homomorphic evaluation can also be called homomorphic analysis or homomorphic evaluation. For example, homomorphic encryption can be abbreviated as HE = (HE.Keygen, HE.Enc, HE.Dec, HE.Eval), meaning HE consists of four algorithmic parts.

[0152] To facilitate understanding, the following is a simple introduction to the various stages of the homomorphic encryption process, using an asymmetric encryption scheme as an example (where n is a security parameter):

[0153] (1) Key generation: (pk, evk, sk) ← HE.Keygen(1 n The function outputs a public key (pk), a homomorphic evaluation key (evk), and a private key (sk), where the public key is abbreviated as pk, and pk serves as the homomorphic encryption key K. enc =pk; Homomorphic evaluation key abbreviation K eval The homomorphic evaluation key can also be called the homomorphic computation key; the private key is abbreviated as sk, and sk serves as the homomorphic decryption key K. dec =sk.

[0154] Figure 4 is a schematic diagram of homomorphic key generation. As shown in Figure 4, the key generation device can generate a homomorphic key based on key materials and a key generator. The key materials include the parameters required to generate the homomorphic key. As shown in Figure 4, the key generation device inputs the key materials to the key generator and outputs a homomorphic key, which may include a homomorphic encryption key K. enc Decryption key K dec and compute key K eval The key material can be generated by the key generation device itself or obtained from other devices. This application does not impose any restrictions on the source of the key material.

[0155] It should be noted that the key generation device shown in Figure 4 includes a key generator, which can be understood as a processing unit within the key generation device used to generate homomorphic keys. This key generation device may also include a communication unit, a storage unit, etc. For example, after generating a homomorphic key through the key generator, the key generation device can store the homomorphic key in the storage unit. This allows the key generation device to directly retrieve the homomorphic key from the storage unit when it needs to perform related homomorphic processing based on the key, eliminating the need for real-time homomorphic key generation and reducing the latency of the key generation device in obtaining the homomorphic key.

[0156] For example, homomorphic key generation device A generates homomorphic encryption key K. enc Homomorphic computation key K eval Homomorphic decryption key K dec Among them, the homomorphic encryption key K enc Send the homomorphic computing key K to homomorphic encryption device B. eval Homomorphic decryption key K is sent to homomorphic computing device C. dec Send to homomorphic decryption device D.

[0157] In a homomorphic encryption task, multiple homomorphic encryption devices can encrypt data from different sources, and multiple homomorphic computing devices can perform homomorphic computations. These multiple homomorphic computing devices can perform homomorphic computations in a single-hop manner, for example, each of the multiple homomorphic computing devices performs homomorphic computations and outputs the corresponding computation results, and the management device determines the homomorphic computation result based on the outputs of the multiple homomorphic computing devices; or, the multiple homomorphic computing devices can perform homomorphic computations in a multi-hop manner, for example, the multiple homomorphic computing devices perform homomorphic computations sequentially, the computation result output by the previous homomorphic computing device is input into the next homomorphic computing device, and the computation result output by the last homomorphic computing device is used as the homomorphic computation result.

[0158] A homomorphic encryption task can also have multiple homomorphic decryption devices. The decryption result can be given to multiple data-using devices. Depending on the key deployment, the homomorphic decryption device and the data-using device can be the same or different entities. The keys of multiple homomorphic encryption devices in a homomorphic encryption task can be the same or different.

[0159] (2) Homomorphic encryption: c←HE.Enc pk (m). Homomorphic encryption devices use homomorphic encryption keys K. enc =pk, the homomorphic encryption process is to encrypt a single bit plaintext message m∈{0,1} into ciphertext c.

[0160] Figure 5 is a schematic diagram of a homomorphic encryption process. As shown in Figure 5, the homomorphic encryption device can be based on the homomorphic encryption key K. encThe plaintext m is encrypted into ciphertext c, as shown in Figure 5. The homomorphic encryption device inputs the plaintext m into the homomorphic encryptor, and the homomorphic encryptor uses the homomorphic encryption key K. enc The plaintext m is encrypted to output ciphertext c. The plaintext m can be generated by the homomorphic encryption device itself or obtained from other devices; this application does not impose any restrictions on the source of the plaintext m.

[0161] It should be noted that the homomorphic encryption device shown in Figure 5 includes a homomorphic encryptor, which can be understood as a processing unit within the homomorphic encryption device, used to perform homomorphic encryption. The homomorphic encryption device may also include a communication unit, a storage unit, etc. For example, after generating ciphertext through the homomorphic encryptor, the homomorphic encryption device can store the ciphertext in the storage unit. This allows the homomorphic encryption device to directly retrieve the ciphertext from the storage unit when it needs to process it subsequently (e.g., to transmit the ciphertext to other devices), without needing to generate the ciphertext in real time, thus reducing the latency of the homomorphic encryption device in retrieving the ciphertext.

[0162] (3) Homomorphic decryption: m←HE.Dec sk (c) The homomorphic decryption device uses the homomorphic decryption key K. dec =sk, the homomorphic decryption process is to decrypt the ciphertext c and restore it to the plaintext message m∈{0,1}.

[0163] Figure 6 is a schematic diagram of a homomorphic decryption process. As shown in Figure 6, the homomorphic decryption device can decrypt based on the decryption key K. dec The ciphertext c is restored to plaintext m, as shown in Figure 6. The homomorphic decryption device inputs the ciphertext c to the homomorphic decryptor, and the homomorphic decryptor uses the decryption key K. dec Decrypt the ciphertext c and output the plaintext m.

[0164] It should be noted that the homomorphic decryption device shown in Figure 6 includes a homomorphic decryptor, which can be understood as a processing unit within the homomorphic decryption device, used to perform homomorphic decryption. The homomorphic decryption device may also include a communication unit, a storage unit, etc. For example, after generating plaintext m through the homomorphic decryptor, the homomorphic decryption device can store the plaintext m in the storage unit. This allows the homomorphic decryption device to directly retrieve the plaintext from the storage unit when it needs to process the plaintext (e.g., transmit the plaintext to other devices), without needing to generate the plaintext in real time, thus reducing the latency of the homomorphic decryption device in obtaining the plaintext.

[0165] (4) Homomorphic computation: c f ←HE.Eval evk (f,c1,…,c lThis can also be called homomorphic evaluation. The homomorphic computation process is based on the input ciphertext c1,…,c l Homomorphic computation key K eval Homomorphic computing devices (which may be called HEcalc or HEeval) perform homomorphic computation of the function f: {0,1} under ciphertext. l →{0,1}, obtain the output ciphertext c of the homomorphic computation. f .

[0166] Figure 7 is a schematic diagram of a homomorphic computation process. As shown in Figure 7, the homomorphic computation device can perform computation based on the key K. eval The input ciphertexts c1, ..., c l Homomorphic computation yields c f As shown in Figure 7, the homomorphic computing device inputs ciphertext c1,…,c l To the homomorphic calculator, the key K is calculated in the homomorphic calculator. eval For ciphertext c1, ..., c l Perform calculations and output the ciphertext c. f Homomorphic calculators can also be called homomorphic calculation circuits, homomorphic calculation functions, etc.

[0167] It should be noted that the homomorphic computing device shown in Figure 7 includes a homomorphic calculator, which can be understood as a processing unit within the homomorphic computing device, used to perform homomorphic computation. The homomorphic computing device may also include a communication unit, a storage unit, etc. For example, the homomorphic computing device generates ciphertext c through the homomorphic calculator. f Then, the ciphertext c can be... f Stored in a storage unit to support subsequent homomorphic computing devices that need to process the ciphertext c. f When processing (e.g., when processing the ciphertext c) f The encrypted text can be directly retrieved from the storage unit when transmitted to other devices. f No need for real-time ciphertext processing f This reduces the need for homomorphic computing devices to obtain ciphertext c. f The time delay.

[0168] The homomorphic computation function f described above represents an arithmetic circuit with addition and multiplication gates over a finite field (galois field, GF). Generally, homomorphic computation HE.Eval is decomposed into multiple fundamental operators, such as homomorphic addition c. add ←HE.Add evk (c1,c2) ​​and homomorphic multiplication c mult ←HE.Mult evk (c1,c2).

[0169] For example, the entire homomorphic encryption scheme HE = (HE.Keygen, HE.Enc, HE.Dec, HE.Eval). The entire homomorphic encryption scheme is briefly described below with reference to Figure 8.

[0170] Figure 8 is a schematic diagram of a homomorphic encryption scheme. As shown in Figure 8, the decrypted result of the ciphertext calculation is equivalent to the plaintext calculation result.

[0171] 7. Bootstrapping Key: Bootstrapping is a special technique for processing ciphertext. After processing, it can "refresh" ciphertext with near-critical noise into a new ciphertext with very low noise. The main method is to transform a high-noise ciphertext... Re-encrypt using the new key k2 to create another fully homomorphic ciphertext. Use the new key k2 to encrypt the old key k1 into ciphertext as well. This refers to the bootstrapping key (BSK). The homomorphic computing device then uses homomorphic computation to establish the corresponding homomorphic decryption circuit. By decrypting the inner ciphertext and restoring it to plaintext, we can obtain a brand new low-noise FHE ciphertext under a new key.

[0172] Bootstrap keys, as a type of homomorphic computing key, need to be generated by a key generation device and distributed to homomorphic computing devices. Besides bootstrap keys, another type of homomorphic computing key is the key switching key (KSK). Taking the RLWE homomorphic encryption scheme with a one-party key as an example, assuming the ciphertext... The corresponding key is Homomorphic computation of multiplication of two ciphertexts ct and ct' The corresponding key is After ciphertext multiplication, not only does the ciphertext size expand, but the key also exhibits exponential cross terms. After each ciphertext computation, a relinearization key (i.e., a key transformation key) is needed to convert the ciphertext product into a new ciphertext with the same dimension as the original ciphertext, and eliminate the corresponding key cross terms before proceeding to the next layer of circuit computation.

[0173] 8. Advanced Encryption Standard (AES) Round Key: The AES encryption algorithm uses a fixed-length master key (128 bits, 192 bits, or 256 bits). For example, if the master key length of the AES encryption algorithm is 128 bits, the AES encryption algorithm is denoted as AES-128; similarly, if the master key length of the AES encryption algorithm is 192 bits, the AES encryption algorithm is denoted as AES-192; and if the master key length of the AES encryption algorithm is 256 bits, the AES encryption algorithm is denoted as AES-256.

[0174] The AES-128, AES-192, and AES-256 mentioned above are symmetric block cipher algorithms. It should be understood that symmetric block cipher algorithms can also include other algorithms besides AES-128, AES-192, or AES-256, such as the Snow encryption algorithm, which will not be illustrated here. The following explanation uses AES as an example of a symmetric block cipher algorithm.

[0175] AES encryption requires multiple round keys. These round keys are generated from the master key through a key scheduling process. The master key can also be called the original key; this application does not impose any restrictions on the key name.

[0176] For example, AES-128 (using a 128-bit master key) requires 11 round keys, AES-192 requires 13 round keys, and AES-256 requires 15 round keys.

[0177] After obtaining the round key, a round key addition operation is performed in each round of AES encryption. This round key addition operation involves XORing the current plaintext data (a 4x4 byte matrix) with the round key byte by byte. The round key addition operation is performed at the beginning of each encryption round and at the end of each round. Specifically:

[0178] Before the first round of encryption begins, a round key addition operation is performed, which XORs the initial plaintext with the first round key.

[0179] At the end of each round of encryption, the round key is incremented again using the round key corresponding to that round.

[0180] In the final round of encryption, byte substitution, row shifting, and column obfuscation are not performed; only the round key is added.

[0181] To facilitate understanding, the generation process of AES round keys will be introduced using AES-128 as an example.

[0182] For example, the process of obtaining the round key through key expansion includes the following steps:

[0183] Step 1.1: Divide the original 128-bit key into four 32-bit words in groups of four bytes. These four 32-bit words are denoted as w[0], w[1], w[2] and w[3].

[0184] As shown above, the AES-128 encryption process requires 11 round keys, each of which is 128 bits. Therefore, a total of 44 32-bit words need to be generated to form the 11 128-bit round keys. For example, the 44 32-bit words are denoted as w[i], where i ranges from 0 to 43. For i values ​​of 0, 1, 2, and 3, w[0], w[1], w[2], and w[3] are obtained by dividing the original 128-bit key. For i values ​​of 4 to 43, w[i] needs to be calculated.

[0185] Step 2.1: Calculate w[i]. 4≤i≤43.

[0186] When i is a multiple of 4, w[i] satisfies the following formula: w[i]=w[i-4]⊕T(w[i-1]) (1-1)

[0187] In equation (1-1) above, the symbol “⊕” represents the XOR operation. T represents the transformation function, which includes the bytes substitution operation, the rotWord operation, and the XOR operation between the byte substitution and the round constant (rcon).

[0188] The circular shift operation described above shifts four bytes in a 32-bit byte to the left by one byte. For example, the byte sequence [a,b,c,d] is transformed into [b,c,d,a] after the circular shift operation.

[0189] The byte substitution operation described above is implemented through a substitution box (S-box), which is a predefined 16x16 byte lookup table used to replace one byte with another. This operation is non-linear, which improves the security of the password.

[0190] The round constant (rcon) mentioned above is a round-related constant used to introduce diffusion during key expansion.

[0191] When the value of is not a multiple of 4, w[i] satisfies the following formula: w[i]=w[i-4]⊕w[i-1] (1-2)

[0192] Step 3.1: Generate round keys.

[0193] Each round key consists of four 32-bit words. By dividing the 44 32-bit words w[0] to w

[0043] generated through steps 11 and 2.1 into groups of four in order, 11 round keys can be obtained.

[0194] To make it easier to understand, the key expansion process is briefly described below.

[0195] Assume the original 128-bit key is k = [k0, k1, ..., k 15 The original 128-bit key is divided into four 32-bit words: w[0] = [k0, k1, k2, k3], w[1] = [k4, k5, k6, k7], w[2] = [k8, k9, k3], and w[3] = [k4, k5, k6, k7]. 10 ,k 11 ],w[3]=[k 12 ,k 13 ,k 14 ,k 15 ].

[0196] When calculating w[4], since i = 4 is a multiple of 4, then w[4] = w[0] ⊕ T(w[3]). The process of calculating w[4] is as follows: first, perform a circular shift on w[3] to obtain w. temp Then for w temp Byte substitution yields w temp2 Then w temp2 XORing with the wheel constant (rcon) yields T(w[3]), and finally w[4] = w[0] ⊕ T(w[3]).

[0197] For example, suppose the initial 128-bit AES key is: 3C,A1,OB,21,57,FO,19,16,90,2E,13,80,AC,C1,07,BD. Then the four 32-bit words w[0] = [3C,A1,OB,21], w[1] = [57,FO,19,16], w[2] = [90,2E,13,80], w[3] = [AC,C1,07,BD].

[0198] The round keys for the first round are w[4], w[5], w[6] and w[7]. Since 4 is a multiple of 4, w[4] = w[0] ⊕ T(w[3]).

[0199] The calculation steps for T(w[3]) are as follows:

[0200] w[3]=[AC,C1,07,BD] is obtained by cyclic shifting wtemp =[C1,07,BD,AC];

[0201] w temp = [C1, 07, BD, AC] as input to the S-box, output is w temp2 =[78,C5,7A,91]. This w temp2 =[78,C5,7A,91] is XORed with the first round constant Rconj[1] to obtain T(w[3])=[79,C5,7A,91], therefore W[4]=3C,A1,0B,21⊕79,C5,7A,91=45,64,71,B0.

[0202] The calculations of w[5], w[6] and w[7] are as follows:

[0203] w[5]=w[1]⊕w[4]=57,FO,19,16⊕45,64,71,B0=12,94,68,A6

[0204] w[6]=w[2]⊕w[5]=90,2E,13,80⊕12,94,68,A6=82,BA,7B,26

[0205] w[7]=w[3]⊕w[6]=AC,C1,07,BD⊕82,BA,7B,26=2E,7B,7C,9B

[0206] Therefore, the key for the first round is 45,64,71,B0,12,94,68,A6,82,BA,7B,26,2E,7B,7C,9B.

[0207] 9. Trans-chipper Operation: The trans-chipper operation involved in this application can be understood as converting ciphertext in a non-homomorphic encryption state into ciphertext in a homomorphic encryption state; or, converting ciphertext in a homomorphic encryption state into ciphertext in a non-homomorphic encryption state. For example, the process by which the second communication device mentioned in the following embodiments homomorphically encrypts the first ciphertext to generate the third ciphertext can be called a trans-chipper operation, wherein the first ciphertext is ciphertext encrypted by the first security algorithm and belongs to the ciphertext in a non-homomorphic encryption state, and the third ciphertext is ciphertext encrypted by the second security algorithm (e.g., homomorphic encryption algorithm) and belongs to the ciphertext in a homomorphic encryption state.

[0208] It should be understood that the above-described conversion operation between ciphertext in a non-homomorphic encryption state and ciphertext in a homomorphic encryption state is called a ciphertext conversion operation, which is only an example and does not constitute any limitation on the scope of protection of this application. For example, it can also be called proxy re-encryption (PRE), conversion operation between non-homomorphic encrypted ciphertext and homomorphic encrypted ciphertext, ciphertext conversion, or first operation, etc.

[0209] The aforementioned "ciphertext in homomorphic encryption state" can also be described as "in homomorphic ciphertext state", "in ciphertext state corresponding to homomorphic encryption algorithm", or "in homomorphic state", etc. In this application, the description of the state encrypted by homomorphic encryption algorithm is not limited in any way. In the following text, for the sake of convenience, the state encrypted by homomorphic encryption algorithm is uniformly described as "in homomorphic ciphertext state".

[0210] The preceding text, with reference to Figures 1 and 2, briefly introduced the application scenarios of the communication method provided in this application embodiment, as well as the basic concepts that may be involved in this application embodiment. Within these basic concepts, the homomorphic encryption process and its security were described. As can be seen from the above, homomorphic encryption technology can still perform data computation and generate calculation results even when the data is in a ciphertext state. Furthermore, since homomorphic encryption and ciphertext computation are performed in the same way, any computational operation can be performed. Therefore, AES encryption or decryption operations can also be performed under homomorphic encryption. This process of performing AES encryption and decryption under homomorphically encrypted ciphertext can be understood as a form of encryption conversion, that is, superimposing AES encryption and decryption operations on homomorphically encrypted ciphertext. For ease of understanding, the encryption conversion process is described below with reference to Figure 9.

[0211] Before explaining the AES encryption and decryption operation superimposed on the homomorphic encrypted ciphertext state with reference to Figure 9, a brief introduction to the symbolic representations of plaintext, ciphertext, key, and calculation results involved in this application is given:

[0212] Plaintext: m, for example, the first data in the following embodiment can be denoted as m.

[0213] Symmetric encryption operation: Enc AES (), for example, encryption based on the first security algorithm in the following embodiments can be denoted as Enc. AES ();

[0214] AES Ciphertext: Ciphertext obtained by encrypting using the AES algorithm, which can be denoted as Enc. AES (m), or simply c, for example, the first ciphertext in the following embodiment can be denoted as Enc. AES (m), or c;

[0215] Homomorphic (HE) encryption operation: Enc HE(), for example, encryption based on the second security algorithm in the following embodiments can be denoted as Enc. HE ();

[0216] Homomorphic computation operation: Eval HE ();

[0217] Homomorphic AES ciphertext: Ciphertext obtained by homomorphically encrypting AES ciphertext can be denoted as HE+AES ciphertext, or simply Enc. HE (c);

[0218] Homomorphic ciphertext: Ciphertext obtained by encryption using a homomorphic algorithm, which can be denoted as Enc. HE (m);

[0219] Calculation result: result.

[0220] It should be understood that the symbolic representations of plaintext, ciphertext, key, and calculation results described above are merely examples and do not constitute any limitation on the scope of protection of this application. Plaintext, ciphertext, key, and calculation results in this application can also be represented in other ways, and no specific representation is limited in this application. For example, a symmetric encryption operation can also be denoted as Enc. snow (); For example, homomorphic encryption operations can also be denoted as Enc FHE (), etc., will not be listed here.

[0221] Figure 9 is a schematic diagram of the declassification process. As shown in Figure 9, the declassification process includes the following steps:

[0222] Step 1.2: The client uploads the ciphertext c and the homomorphically encrypted key k to the server. Here, key k is the AES key, and the homomorphically encrypted key k can be denoted as Enc. HE (k). The client uses AES key k to encrypt user data m, obtaining ciphertext c, and then encrypts key k using a homomorphic encryption algorithm, obtaining Enc. HE (k).

[0223] Step 2.2: The server encrypts the ciphertext c using a homomorphic encryption algorithm, generating a double-encrypted (HE+AES) ciphertext Enc. HE (c)

[0224] Step 3.2: The server uses the key Enc in the homomorphic encryption state. HE (k), for the ciphertext Enc in the homomorphic encryption state HE (c) Perform AES decryption calculation.

[0225] For example, Eval HE (E -1) = Eval HE (AES -1 (k,c)) generates Enc HE (m), Enc HE (m) is in the ciphertext state corresponding to homomorphic encryption.

[0226] Step 4.2: Process the ciphertext Enc HE (m) performs homomorphic computation to obtain the homomorphic computation result in the encrypted state.

[0227] However, during the encryption process shown in Figure 9, the server needs to process the ciphertext Enc... HE (c) During the decryption process, based on steps 1.1 to 3.4 described above, the Enc in the homomorphic ciphertext state is... HE (k) Performing key expansion to generate round keys has high computational complexity and prolongs decryption time.

[0228] This application provides a communication method that aims to reduce data transmission overhead while ensuring data security.

[0229] It should be understood that the embodiments shown below do not particularly limit the specific structure of the execution subject of the method provided in the embodiments of this application, as long as it is possible to communicate according to the method provided in the embodiments of this application by running a program that records the code of the method provided in the embodiments of this application. For example, the execution subject of the method provided in the embodiments of this application may be a network element or device; or, it may be a functional module in a network element or device that can call and execute a program.

[0230] Figure 10 is a schematic flowchart of a communication method provided in this application. It includes the following steps:

[0231] S1010, the first communication device encrypts the first data based on N first keys corresponding to the first security algorithm to obtain the first ciphertext.

[0232] In this application, the first security algorithm can be a symmetric block cipher algorithm. For example, the first security algorithm can be AES encryption algorithm, Snow encryption algorithm, or other symmetric block cipher algorithms.

[0233] Furthermore, in this application, the first security algorithm can be a security algorithm included in a first security context, and the encryption key included in the first security context can be called the first security key, which can be understood as the master key of the first security algorithm. Therefore, in this application, the first security algorithm can also be described as the first security context, the first security key, or a block security algorithm, etc. When the first security algorithm is described as the first security context, it means that the corresponding steps are performed based on the security algorithm and / or the security key included in the first security context; when the first security algorithm is described as the first security key, it means that the corresponding steps are performed based on the first security key and / or the security algorithm corresponding to the first security key. In this application, the name of the first security algorithm is not limited, and multiple keys are required in the encryption and / or decryption process based on the first security algorithm.

[0234] The communication method in this application can be executed by a first communication device, a component within the first communication device, or a logic module or software capable of implementing all or part of the functions of the first communication device. The component within the first communication device can be a module, processor, chip, or chip system, etc. The communication module within the first communication device can be a circuit or chip responsible for communication functions within the first communication device. This circuit or chip can be a modem chip (also known as a baseband chip), or a SoC chip or SIP chip containing a modem core.

[0235] Furthermore, the first communication device in this application can be one device or multiple devices. For example, the first communication device includes multiple devices, and different devices can perform different steps. For instance, the first communication device includes device #1 and device #2, where device #1 is used to generate a first ciphertext and N second keys, and device #2 is used to send the first ciphertext and N second keys to the second communication device. That is to say, the function of the first communication device may be performed by multiple devices respectively. For ease of description, the following description uses the execution of the communication method by the first communication device as an example.

[0236] For example, the first communication device may be a client device, a terminal device, a consumer device, an artificial intelligence user (AI user) device, etc.

[0237] The N first keys corresponding to the aforementioned first security algorithm, where N is an integer greater than 1, can be understood as: multiple keys are required during the encryption and decryption process based on this first security algorithm. These multiple first keys can be generated based on the master key corresponding to this first security algorithm. The master key can also be called the original key.

[0238] For example, if the first security algorithm is the AES-128 encryption algorithm described in the basic concepts section above, then the N first keys can be the 11 round keys corresponding to the AES-128 encryption algorithm introduced in the basic concepts section above. The generation process of these 11 round keys can be referred to the description in the basic concepts section above, and will not be repeated here. Among them, the N first keys can be denoted as rk1, rk2, rk3...rkN.

[0239] For example, the first communication device encrypts the first data based on N first keys corresponding to the first security algorithm to obtain the first ciphertext. This can be achieved by the first communication device encrypting the first data separately using each of the N first keys to obtain the first ciphertext. The first data can be plaintext data to be processed by the first communication device, or it can be plaintext data to be processed by another device, which can send the first data to be analyzed to the first communication device. This application does not limit the method by which the first communication device obtains the first data.

[0240] For example, the first data may include M data groups (or M groups of data). The first communication device encrypts each of the M data groups based on N first keys to obtain M ciphertexts. These M ciphertexts are then combined to obtain the first ciphertext. For instance, the first data is denoted as m, and the N first keys are denoted as rk1, rk2, rk3…rkN. Taking the AES algorithm as an example, the first security algorithm is denoted as AES, and the encryption operation based on the first security algorithm is denoted as Enc. AES The first data is divided into M data groups (m1, m2, m3…mM). The first communication device encrypts m1 based on rk1, rk2, rk3…rkN to obtain Enc. AES (m1), and then based on rk1, rk2, rk3…rkN, m2, m3…mM are encrypted sequentially to obtain Enc AES (m2), Enc AES (m3)...Enc AES (mM), finally Enc AES (m1), Enc AES (m2), Enc AES (m3)...Enc AES (mM) merged to obtain Enc AES (m), the Enc AES(m) is the first ciphertext mentioned above.

[0241] It should be understood that the specific process by which the first communication device encrypts the first data based on N first keys to obtain the first ciphertext is not described in detail in this application. For details, please refer to the description of encrypting plaintext data based on the AES encryption algorithm in the current related technologies.

[0242] Optionally, before encrypting the first data based on the N first keys corresponding to the first security algorithm, the first communication device has already determined the first security algorithm. For example, the first communication device can negotiate and determine the required first security algorithm with the communication object (e.g., the second communication device). In this case, the method flow shown in FIG10 may further include:

[0243] S1001, the first communication device and the second communication device negotiate and determine the first security algorithm.

[0244] The communication method in this application can be executed by a second communication device, a component within the second communication device, or a logic module or software capable of implementing all or part of the functions of the second communication device. The component in the second communication device can be a module, processor, chip, or chip system, etc., in the first communication device. The communication module in the second communication device can be a circuit or chip responsible for communication functions within the second communication device. This circuit or chip can be a modem chip (also known as a baseband chip), or a SoC chip or SIP chip containing a modem core.

[0245] Furthermore, the second communication device in this application can be one device or multiple devices. For example, the first communication device includes multiple devices, and different devices can perform different steps. For instance, the second communication device includes device #3 and device #4, where device #3 is used to obtain the third ciphertext as described below, and device #4 is used to decrypt the third ciphertext. In other words, the function of the second communication device may be performed separately by multiple devices. For ease of description, the following explanation uses the second communication device performing the communication method as an example.

[0246] For example, the first communication device may be a server, a producer device, a network device, or an artificial intelligence agent (AI agent) device, etc.

[0247] For example, the first communication device and the second communication device negotiate to determine the first security algorithm, including: the first communication device and the second communication device negotiate to determine the algorithm type and / or the algorithm length of the first security algorithm. For example, the first communication device and the second communication device negotiate to determine that the first security algorithm is a symmetric block encryption algorithm; or, for example, the first communication device and the second communication device negotiate to determine that the algorithm length corresponding to the first security algorithm is 128 bits, 192 bits, or 256 bits, etc.

[0248] For ease of description, this application uses AES-128 encryption algorithm as the first security algorithm as an example. However, it should be understood that this application does not limit the first security algorithm to AES encryption algorithm. For example, the first security algorithm can also be other block cipher algorithms, such as AES-256 encryption algorithm, data encryption standard (DES) algorithm, 5G Snow algorithm, etc.

[0249] By way of example and not limitation, the first communication device in this application may determine the first security algorithm in a manner other than negotiation with the second communication device. For example, the first security algorithm may be pre-configured, and the first and second communication devices may determine the first security algorithm based on pre-configured information.

[0250] For example, the protocol predefines or the management device pre-configures the algorithm type and / or algorithm length of the symmetric block cipher algorithm used between the first and second communication devices. For instance, the management device pre-configures a strategy for data transmission between the first and second communication devices, instructing the symmetric block cipher algorithm to use AES-128. The first and second communication devices encrypt or decrypt data transmitted between them based on the AES-128 algorithm according to this strategy. Alternatively, the protocol specifies that the first and second communication devices use the AES-128 algorithm to encrypt or decrypt data transmitted between the second communication device and the first network element. Here, the management device can be understood as a device in the communication system that manages all communication devices and can configure algorithms for the communication devices in the system. It should be understood that after determining the first security algorithm, the first communication device can determine the number of round keys based on the algorithm length corresponding to the first security algorithm, execute a round key expansion algorithm to obtain the aforementioned N first keys, and encrypt plaintext data based on these N first keys to generate the first ciphertext. Optionally, the first communication device may cache N first keys locally.

[0251] In this application, the first communication device can also obtain N second keys based on the second security algorithm and the aforementioned N first keys. Therefore, the method flow shown in Figure 10 further includes:

[0252] S1020, the first communication device encrypts N first keys respectively based on the second security algorithm to obtain N second keys.

[0253] For example, the ciphertext encrypted by the second security algorithm can be processed in its ciphertext state. Alternatively, the N second keys can enable the decryption of ciphertext obtained based on the first security algorithm in its ciphertext state corresponding to the second security algorithm.

[0254] It should be understood that in this communication method, the second communication device directly expands the master key in plaintext state to obtain N first keys, and then sends the N first keys to the first communication device to support the first communication device in encrypting based on the N first keys to obtain N second keys. This is not done by expanding the master key in ciphertext state to obtain N round keys.

[0255] It should be understood that if the ciphertext is in the ciphertext state corresponding to the first security algorithm and in the plaintext state corresponding to the second security algorithm, then the aforementioned N first keys can be used to decrypt the ciphertext, and the result is in the plaintext state corresponding to the first security algorithm. If the ciphertext is in the ciphertext state corresponding to the first security algorithm and in the ciphertext state corresponding to the second security algorithm, then the N second keys obtained by encrypting the N first keys based on the second security algorithm can be used to decrypt the ciphertext, and the result is in the plaintext state corresponding to the first security algorithm, but still in the ciphertext state corresponding to the second security algorithm. Furthermore, during the decryption process, the N second keys remain in the ciphertext state corresponding to the second security algorithm.

[0256] For example, the first communication device encrypts N first keys based on a second security algorithm to obtain N second keys, including but not limited to the following possible implementations:

[0257] As one possible implementation, during the execution of step S1010 above, the first communication device encrypts the first data based on N first keys to obtain the first ciphertext, and can encrypt the N first keys respectively to obtain N second keys.

[0258] In this implementation, when the first communication device executes step S1010, it can generate N first keys based on the first security algorithm, perform homomorphic encryption on the N first keys to generate N second keys, and cache the N second keys. Subsequently, the cached N second keys can be provided to the second communication device.

[0259] As another possible implementation, during the execution of step S1001 described above, the first communication device can generate N first keys when negotiating and determining the first security algorithm. These N first keys are used to generate N second keys.

[0260] In this implementation, when executing step S1001, the first communication device can generate N first keys based on the first security algorithm. These N first keys can be used to encrypt the first data in step S1010 to obtain the first ciphertext. These N first keys can also be used in the homomorphic encryption process of step S1020 to obtain N second keys.

[0261] It should be understood that the above two implementation methods are merely illustrative of the timing when the first communication device generates N second keys, and do not constitute any limitation on the scope of protection of this application. The first communication device may generate the N second keys at other times. For example, the first communication device may generate N second keys after receiving a key request from the second communication device, and provide the N second keys to the second communication device. Examples will not be provided here.

[0262] In this application, the second security algorithm can be a homomorphic encryption algorithm. A description of homomorphic encryption algorithms can be found in the basic concepts section above, and will not be repeated here. For example, the ciphertext encrypted by this second security algorithm can be processed in its ciphertext state.

[0263] The ciphertext encrypted by the second security algorithm mentioned above can also be described as being processed in the ciphertext state: the ciphertext is in the ciphertext state corresponding to the second security algorithm; or, the ciphertext is in the ciphertext state corresponding to the second security algorithm.

[0264] Furthermore, the second security algorithm in this application can be a security algorithm included in a second security context, and the encryption key included in the second security context can be called a second security key. Therefore, the second security algorithm in this application can also be described as a second security context, a second security key, or a homomorphic security algorithm, etc. When the second security algorithm is described as a second security context, it means that the corresponding steps are performed based on the security algorithm and / or security key included in the second security context; when the second security algorithm is described as a second security key, it means that the corresponding steps are performed based on the second security key and / or the security algorithm corresponding to the second security key. This application does not limit the name of the second security algorithm; the ciphertext encrypted based on the second security algorithm only needs to be processed in the ciphertext state.

[0265] In this application, the N first keys are encrypted using a second security algorithm to obtain N second keys, including but not limited to the following implementation methods:

[0266] As one possible implementation, the aforementioned N second keys are N keys obtained by encrypting N first keys respectively based on the second security algorithm. For example, the first communication device encrypts the N first keys respectively based on the encryption key corresponding to the second security algorithm to obtain N second keys.

[0267] In this implementation, the N first keys can be denoted as rk1, rk2, rk3…rkN. Taking the second security algorithm as a homomorphic encryption algorithm as an example, denoted as HE, the encryption operation based on the second security algorithm can be represented as Enc. HE Then N second keys can be denoted as Enc HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN).

[0268] As another possible implementation, the aforementioned N second keys are determined based on N third keys, which are obtained by encrypting the N first keys respectively using a second security algorithm. For example, the first communication device encrypts the N first keys respectively using the encryption key corresponding to the second security algorithm to obtain N third keys, and then determines the N second keys based on these N third keys.

[0269] In this implementation, the N third keys can be understood as intermediate keys or intermediate quantities in the process of encrypting the N first keys based on the second security algorithm to determine the N second keys.

[0270] For example, determining N second keys based on N third keys can be achieved by processing the N third keys based on a security mode (e.g., cipher block chaining (CBC) mode) to obtain N second keys.

[0271] To facilitate understanding, the process of determining N second keys based on N third keys is briefly described below with reference to Figure 11.

[0272] As shown in Figure 11, the N first keys are encrypted using the second security algorithm, resulting in N third keys, including third key #1, third key #2, and third key #3, as shown in Figure 11. HE (rk1), Enc HE (rk2) and Enc HE(rk3). The N second keys include second key #1, second key #2 and second key #3, as shown in Figure 11 as chipertext1, chipertext2 and chipertext3.

[0273] As shown in Figure 11, the process of processing the third key #1, third key #2, and third key #3 based on the security mode to obtain the second key #1, second key #2, and second key #3 is as follows:

[0274] The second key #1 is determined based on the initialization vector (IV) and the third key #1; then, the second key #2 is determined based on the second key #1 and the third key #2, and the second key #3 is determined based on the second key #2 and the third key #3. The determination of the second key #1 based on the initialization vector and the third key #1 can be achieved by XORing the initialization vector and the third key #1 by a specific bit order. For example, the initialization vector, the third key #1, and the second key #1 satisfy the following relationship:

[0275] chipertext1 = Enc HE (rk1)⊕IV, where chipertext1 represents the second key #1, Enc HE (rk1) represents the third key #1, IV represents the initial vector, and ⊕ represents the XOR operation.

[0276] Similarly, determining the second key #2 based on the second key #1 and the third key #2 can be achieved by XORing the second key #1 and the third key #2 according to their bitwise operations. For example, the second key #1, the third key #2, and the second key #2 satisfy the following relationship:

[0277] chipertext2 = Enc HE (rk2)⊕chipertext1, where chipertext2 represents the second key #2, Enc HE (rk2) represents the third key #2, chipertext1 represents the second key #1, and ⊕ represents the XOR operation.

[0278] Determining the second key #3 based on the second key #2 and the third key #3 can be achieved by XORing the second key #2 and the third key #3 according to their bitwise operations. For example, the second key #2, the third key #3, and the second key #3 satisfy the following relationship:

[0279] Chipertext3=Enc HE (rk3)⊕chipertext2, where chipertext3 represents the second key #3, EncHE (rk3) represents the third key #3, chipertext2 represents the second key #2, and ⊕ represents the XOR operation.

[0280] As described above, the N second keys can be chipertext1, chipertext2, and chipertext3 as shown in Figure 11. In this implementation, the second communication device can reconstruct the N third keys based on the received N second keys. For example, based on the received chipertext1, chipertext2, and chipertext3, the secure connection mode shown in Figure 11 is input in reverse to determine the N third keys Enc. HE (rk1), Enc HE (rk2) and Enc HE (rk3).

[0281] It should be understood that the two possible implementations described above are merely illustrative examples of how to determine N second keys based on the second security algorithm and N first keys, and do not constitute any limitation on the scope of protection of this application. In this application, the method by which the first communication device determines N second keys based on the second security algorithm and N first keys can also exist in other ways. For example, after the first communication device encrypts each of the N first keys based on the encryption key corresponding to the second security algorithm, it can also perform other processing methods besides the aforementioned secure connection to obtain N second keys. The second communication device only needs to be able to recover N third keys based on the N second keys. Further details will not be elaborated here.

[0282] Optionally, before the first communication device performs encryption based on the N first keys of the second security algorithm, the first communication device has already determined the second security algorithm and the encryption key corresponding to the second security algorithm. For example, the first communication device can negotiate and determine the required second security algorithm with the communication object (e.g., the second communication device). Then, the method flow shown in FIG10 may further include:

[0283] S1002, the first communication device and the second communication device negotiate and determine the second security algorithm.

[0284] For example, the first communication device and the second communication device negotiate to determine a second security algorithm, including: the first communication device and the second communication device negotiate to determine the algorithm type of the second security algorithm. For example, the first communication device and the second communication device negotiate to determine that the second security algorithm is a homomorphic encryption algorithm.

[0285] Optionally, the homomorphic encryption algorithms involved in this application include, but are not limited to:

[0286] The following algorithms are used: RSA, TFHE, ElGamal, Paillier, Boneh-Goh-Nissim, Gentry, BGV, BFV, GSW, THEW, Fast HEM Cryptosystem with Worst-case to Average-case Reductions (FHEW), and the Cheon-Kim-Kim-Song Homomorphic Encryption Scheme (CKKS). This application does not limit the homomorphic algorithm upon which the homomorphic encryption is based; for ease of description, the CKKS algorithm will be used as an example of the second secure algorithm in the following description.

[0287] By way of example and not limitation, the first communication device may determine the second security algorithm in a manner other than negotiation with the second communication device. For example, the second security algorithm may be pre-configured, and the first and second communication devices may determine the second security algorithm based on pre-configuration information.

[0288] For example, the protocol predefines or the management device preconfigures the type of homomorphic encryption algorithm used between the first and second communication devices. For instance, the management device preconfigures a encryption strategy for the first and second communication devices, which specifies that the homomorphic encryption part uses the CKKS algorithm. Or, the protocol specifies that the first and second communication devices use a predefined security protocol and / or algorithm (e.g., the TLS protocol) for security protection, and the predefined protocol specifies that the CKKS algorithm is used for homomorphic encryption protection.

[0289] Furthermore, the first communication device determines the homomorphic encryption key and the homomorphic decryption key. The second communication device determines the homomorphic encryption key. The homomorphic encryption key can be simply referred to as the encryption key, or denoted as pk. The homomorphic encryption key can also be called the public key, and the homomorphic decryption key can also be called the private key.

[0290] As one possible implementation, the first communication device determines the homomorphic encryption key and the homomorphic decryption key by generating sk based on the security parameters corresponding to the second security algorithm, and then generating pk based on sk. The second communication device determines the homomorphic encryption key by sending the generated pk to the second communication device.

[0291] As another possible implementation, the first communication device determines the homomorphic encryption key and the homomorphic decryption key by requesting the homomorphic encryption key and the homomorphic decryption key corresponding to the second security algorithm from a key generation center. The second communication device determines the homomorphic encryption key by requesting the homomorphic encryption key corresponding to the second security algorithm from a key generation center. Here, the key generation center can be understood as a device in the communication system used to manage all security keys. This key generation center can also be called a key management center, key management device, etc.

[0292] It should be understood that the methods described above for the first communication device to determine the homomorphic encryption key and the homomorphic decryption key, and for the second communication device to determine the homomorphic encryption key, are merely examples and do not constitute any limitation on the scope of protection of this application. For example, the first communication device may also determine the homomorphic encryption key and the homomorphic decryption key based on historical communication data.

[0293] For example, after the first communication device generates the first ciphertext and N second keys, it can provide the first ciphertext and N second keys to the second communication device, so that the second communication device can encrypt the first ciphertext based on the second security algorithm to obtain the third ciphertext, and decrypt the third ciphertext based on the received N second keys to obtain the second ciphertext in a homomorphic ciphertext state. As can be seen from the above, the ciphertext in the homomorphic ciphertext state supports processing in the ciphertext state, so the second ciphertext can be processed in the ciphertext state. The method flow shown in Figure 10 also includes:

[0294] S1030, the first communication device sends a first ciphertext and N second keys to the second communication device, and correspondingly, the second communication device receives the first ciphertext and N second keys from the first communication device.

[0295] Optionally, the first communication device sending the first ciphertext and N second keys to the second communication device can be achieved by the first communication device sending the first ciphertext and N second keys to the second communication device through the same or different messages. For example, the N second keys are carried in the first message, and the first ciphertext is carried in the second message, where the first message and the second message are the same or different messages.

[0296] For example, the first communication device may also send first indication information and / or second indication information to the second communication device. The first indication information is used to indicate the length of the first key, and the second indication information is used to indicate the first security algorithm and / or the second security algorithm. For example, the first indication information is used to indicate that the length of the first key is 128 bits, 192 bits, or 256 bits, etc.; and for example, the second indication information is used to indicate that the first security algorithm is AES symmetric block encryption algorithm, and the second security algorithm is CKKS homomorphic encryption algorithm, etc.

[0297] For ease of understanding, the following will explain the sending of N second keys from the first communication device to the second communication device, and the sending of the first ciphertext from the first communication device to the second communication device.

[0298] The following is an explanation of how the first communication device sends N second keys to the second communication device:

[0299] For example, the first communication device sends the aforementioned N second keys to the second communication device, including but not limited to the following possible implementations:

[0300] As one possible implementation, the first communication device can sequentially send the aforementioned N second keys to the second communication device.

[0301] In this implementation, the first ciphertext includes M block ciphertexts, where M is an integer greater than 1. The first communication device sends the first ciphertext and N second keys to the second communication device, including: first sending the first block ciphertext from the M block ciphertexts, then sequentially sending the N second keys based on the decryption process of the first block ciphertext by the second communication device, and after the first block ciphertext is decrypted, sequentially sending the block ciphertexts from the M block ciphertexts excluding the first block ciphertext.

[0302] Under this technical solution, the first communication device does not need to provide N second keys at once. Instead, it provides the keys required by the second communication device sequentially based on the decryption progress of the second communication device, which can reduce the key transmission overhead to a certain extent. For example, in the event of a decryption error or malfunction by the second communication device, it is not necessary to provide subsequent keys.

[0303] To facilitate understanding, the process of the first communication device sequentially sending the aforementioned N second keys to the second communication device is briefly explained using two examples:

[0304] Example 1: N first keys are denoted as rk1, rk2, rk3...rkN, and M block ciphertexts are denoted as c1, c2, c3...cM.

[0305] Step 1.3: The first communication device sends c1 to the second communication device.

[0306] Step 2.3: The second communication device receives c1 and sends a response message #1 to the first communication device, which indicates that c1 was successfully received.

[0307] Step 3.3: After receiving response message #1, the first communication device determines the second key #1 for encryption using the second security algorithm, such as Enc. HE (rk1) sends the Enc to the second communication device. HE(rk1). Optionally, the generator that generated the Enc may also be sent to a second communication device. HE The identifier of rk1 in (rk1).

[0308] Step 4.3: The second communication device receives Enc HE (rk1), encrypts c1 using the second security algorithm to generate Enc. HE (c1), then based on Enc HE (rk1) for Enc HE (c1) Decrypts the encryption under the second security algorithm to obtain the intermediate ciphertext Enc of c1. HE (c1.1). Send response message #2 to the first communication device, which indicates that the intermediate ciphertext Enc has been successfully decrypted. HE (c1.1).

[0309] Step 5.3: After receiving response message #2, the first communication device determines the second key #2 encrypted by the second security algorithm, such as Enc. HE (rk2), send the Enc to the second communication device. HE (rk2). Optionally, the generator that generated the Enc may also be sent to a second communication device. HE The identifier of rk2 in (rk2).

[0310] Step 6.3: The second communication device receives Enc HE (rk2), then based on Enc HE (rk2) for Enc HE (c1) Decrypts the encryption under the second security algorithm to obtain the intermediate ciphertext Enc of c1. HE (c1.2). Send response message #3 to the first communication device, which indicates that the intermediate ciphertext Enc has been successfully decrypted. HE (c1.2).

[0311] Repeat steps 5.3 and 6.3 above to transmit Enc. HE (rk3) to Enc HE (rkN), until the second communication device completes the decryption of c1 and obtains Enc. HE (m1). The second communication device can decrypt c1 by instructing the first response message.

[0312] Furthermore, the first communication device sends c2, c3…cM to the second communication device, which decrypts c2, c3…cM based on the N second keys received above, to obtain Enc. HE (m2), Enc HE (m3)...Enc HE(mM). Among them, Enc HE (m1), Enc HE (m2), Enc HE (m3)...and Enc HE (mM) are combined to obtain the decryption result of the first ciphertext encrypted by the second communication device based on N second key pairs and the second security algorithm. This decryption result is the first data encrypted based on the second security algorithm, which can be denoted as Enc. HE (m).

[0313] Example 2: N first keys are denoted as rk1, rk2, rk3...rkN, and M block ciphertexts are denoted as c1, c2, c3...cM.

[0314] Step 1.4: The first communication device sends c1 to the second communication device.

[0315] Step 2.4: The second communication device receives c1 and sends a response message #1 to the first communication device, which indicates that c1 was successfully received.

[0316] Step 3.4: After receiving response message #1, the first communication device determines the third key #1 encrypted by the second security algorithm, such as Enc. HE (rk1), and determine the second key #1 based on the third key #1, such as chipertext1. Send chipertext1 to the second communication device. Optionally, the identifier of rk1 that generated chipertext1 may also be sent to the second communication device.

[0317] Step 4.4: The second communication device receives chipertext1 and encrypts c1 using the second security algorithm to generate Enc. HE (c1), then determine Enc based on chipertext1. HE (rk1), and based on Enc HE (rk1) for Enc HE (c1) Decrypts the encryption under the second security algorithm to obtain the intermediate ciphertext Enc of c1. HE (c1.1). Send response message #2 to the first communication device, which indicates that the intermediate ciphertext Enc has been successfully decrypted. HE (c1.1).

[0318] Step 5.4: After receiving response message #2, the first communication device determines the third key #2 encrypted by the second security algorithm, such as Enc. HE(rk2), and determine the second key #2 based on the third key #2, such as chipertext2. Send chipertext2 to the second communication device. Optionally, the identifier of rk2 that generated chipertext2 may also be sent to the second communication device.

[0319] Step 6.4: The second communication device receives chipertext2, and then determines Enc based on chipertext2. HE (rk2), and based on Enc HE (rk2) for Enc HE (c1) Decrypts the encryption under the second security algorithm to obtain the intermediate ciphertext Enc of c1. HE (c1.2). Send response message #3 to the first communication device, which indicates that the intermediate ciphertext Enc has been successfully decrypted. HE (c1.2).

[0320] Repeat steps 5.4 and 6.4 above, transmitting chipertext3 to chipertextN until the second communication device completes decryption of c1 and obtains Enc. HE (m1).

[0321] Furthermore, the first communication device sends c2, c3…cM to the second communication device, which decrypts c2, c3…cM based on the N second keys determined above, to obtain Enc. HE (m2), Enc HE (m3)...Enc HE (mM). Among them, Enc HE (m1), Enc HE (m2), Enc HE (m3)...and Enc HE (mM) are combined to obtain the decryption result of the first ciphertext encrypted by the second communication device based on N second key pairs and the second security algorithm. This decryption result is the first data encrypted based on the second security algorithm, which can be denoted as Enc. HE (m).

[0322] It should be understood that the above-described process of the first communication device sequentially sending the above-described N second keys to the second communication device is merely an example and does not constitute any limitation on the scope of protection of this application. The first communication device may also sequentially send the above-described N second keys to the second communication device in other ways, such as sending N second keys sequentially at a predefined time interval if no signal indicating a decryption error is received from the second communication device. Examples will not be provided here.

[0323] As another possible implementation, the first communication device can send N second keys to the second communication device at once. In this implementation, the first communication device can provide N second keys to the second communication device uniformly without needing to concern itself with the decryption process of the second communication device, thus reducing the complexity of the key provision process for the first communication device to some extent.

[0324] For example, the first communication device provides the aforementioned N second keys to the second communication device via a first message, wherein the first message carries the aforementioned N second keys. Optionally, the first message may also include N key identifiers, which are used to identify the N second keys respectively.

[0325] As another possible implementation, the first communication device can combine N second keys into a single key and send it to the second communication device. In this implementation, the first communication device can combine the N second keys and send the combined key to the second communication device, which can then reconstruct the required N second keys based on the combined key. By processing the key, the security of key transmission can be improved to a certain extent.

[0326] For example, the first communication device providing the aforementioned N second keys to the second communication device via a first message could be: the first message carries key #1, which is a key determined based on the aforementioned N second keys. For instance, the N second keys might be Enc... HE (rk1), Enc HE (rk2), Enc HE (rk3)...Enc HE (rkN), key #1 can be denoted as Enc HE (rk1, rk2, rk3…rkN); N second keys are chipertext1, chipertext2, chipertext3…chipertextN, and key #1 can be denoted as chipertext1...N.

[0327] It should be understood that the above-mentioned methods of sending N second keys are merely examples and do not constitute any limitation on the scope of protection of this application. The first communication device may also send N second keys in other ways, such as sending a certain second key among the N second keys, as well as the difference between the other second keys and the second key, etc., which will not be illustrated here.

[0328] For example, in this application, the first communication device can provide the aforementioned N second keys to the second communication device if the first security algorithm is a non-shared security algorithm. For instance, sending N second keys from the first communication device to the second communication device includes: the first communication device can send N second keys to the second communication device if the first security algorithm is a non-shared security algorithm. It should be understood that if the first security algorithm is a shared security algorithm, the second communication device can determine the N first keys based on the first security algorithm itself, and then encrypt the N first keys separately based on the second security algorithm to obtain the required N second keys, without the first communication device providing them to the second communication device. Sending N second keys to the second communication device when the first security algorithm is determined to be a non-shared security algorithm can avoid unnecessary key transmission overhead to a certain extent.

[0329] Optionally, the first communication device may determine that the first security algorithm is a non-shared security algorithm based on the communication method between the first communication device and the second communication device. For example, if the first communication device is a UE and the second communication device is an NF, and the pre-configured communication method between the UE and the NF indicates a pre-shared key, then the first communication device may determine that the first security algorithm is a shared security algorithm based on the communication method between the first communication device and the second communication device; if the communication method between the NF and the AF indicates that there is no pre-shared key, then the first communication device may determine that the first security algorithm is a non-shared security algorithm based on the communication method between the first communication device and the second communication device.

[0330] It should be noted that the above-mentioned example of the first communication device sending N second keys to the second communication device when the first security algorithm is a non-shared security algorithm is merely an example and does not constitute any limitation on the scope of protection of this application. For example, the first communication device may not be sure whether the first security algorithm is a non-shared algorithm, or even if the first security algorithm is a shared algorithm, the first communication device may still provide the above-mentioned N second keys to the second communication device.

[0331] The following is an explanation of how the first communication device sends the first encrypted message to the second communication device:

[0332] For example, the first communication device sending the first ciphertext to the second communication device can be: the first communication device sending a second message to the second communication device, the second message including the first ciphertext.

[0333] Optionally, the second message may also include an identifier of a first session, which is used to transmit at least one ciphertext, and the first ciphertext may be one of the at least one ciphertext. The identifier of the first session is associated with the aforementioned N second keys.

[0334] As an example and not a limitation, the first session can be a PDU session, a Quic session, or a Hypertext Transfer Protocol (HTTP) session, etc. For example, the identifier of the first session can be a PDU session ID.

[0335] In this application, the first session is used to transmit at least one ciphertext, which can be understood as being associated with at least one service request. For example, the first communication device may also send a first message #2, which includes a first identifier and a first ciphertext #2, wherein the first ciphertext #2 is one of the at least one ciphertexts mentioned above.

[0336] In this application, the first communication device and the second communication device can establish the aforementioned first session through a session creation process. For example, the method flow shown in Figure 10 further includes the following steps:

[0337] S1003, the first communication device sends a third message to the second communication device, and correspondingly, the second communication device receives the third message from the first communication device.

[0338] This third message is used to request the establishment of the first session. For example, the first session could be an AI service session, which can be understood as a session related to services in an AI scenario, such as an AI data analysis session, an AI inference session, or other AI-related sessions.

[0339] In this application, an AI service session can be understood as a session used to perform AI services such as AI inference and AI training requests. For example, an AI service session is a session established between an AI user and an AI agent to perform AI services. If the first communication device is the AI ​​user and the second communication device is the AI ​​agent, the process of the AI ​​user sending an AI inference request message to the AI ​​agent and the AI ​​agent returning the AI ​​inference result to the AI ​​user is the process by which the AI ​​agent provides AI inference services to the AI ​​user.

[0340] For example, the transport protocol for an AI service session can be HTTP or Quick User Datagram Protocol (Quic UDP), and will not be listed in detail here.

[0341] Optionally, this third message may be called an AI inference session creation request message.

[0342] For example, the third message includes at least one of the following:

[0343] The identifier of the first session, the identifier of the first communication device, the information of the second security algorithm, or the information of the first security algorithm.

[0344] The identifier for the first session is used to identify the first session. For example, the first session is an AI session, and the identifier for the first session can be a PDU session ID. In this application, the first session can be associated with at least one data analysis request. For example, the data to be analyzed by the first communication device includes first data, second data, and third data, and the ciphertexts corresponding to the first data, second data, and third data can all be transmitted via the first session.

[0345] The identifier of the first communication device is used to identify the first communication device. For example, if the first communication device is a terminal device, the identifier of the first communication device may be the identifier of the terminal device such as SUCI or GUTI; if the first communication device is an OTT user, the identifier of the first communication device may be the identifier of the OTT user; if the first communication device is an AF, the identifier of the first communication device may be the identifier of the AF.

[0346] The information regarding the second security algorithm includes details related to that algorithm. For example, this information might include the algorithm's type, length, corresponding key information, or parameters. The key information could be an identifier for the key, such as the identifier of the PK key.

[0347] Information about the first security algorithm refers to information related to the first security algorithm. For example, information about the first security algorithm may include its type, length, or parameters.

[0348] Optionally, the information of the second security algorithm and / or the information of the first security algorithm may be explicitly or implicitly indicated, for example, the name of the third message may include an algorithm information field that indicates a homomorphic security algorithm and / or a symmetric group security algorithm.

[0349] S1004, the second communication device sends a fifth message to the first communication device, and correspondingly, the first communication device receives the fifth message from the second communication device.

[0350] This fifth message responds to the third message mentioned above; for example, the fifth message could be called the AI ​​inference session creation response message. This fifth message is used to indicate whether the first session creation was successful or failed.

[0351] Optionally, during the creation of the first session, the identifier of the first session can be carried in the third message sent by the first communication device. Alternatively, it can be an identifier assigned by the second communication device. For example, the second communication device assigns an identifier for identifying the first session in response to the third message. If the identifier of the first session is assigned by the second communication device, the fifth message mentioned above may also include the identifier of the first session.

[0352] For example, in this application, the second communication device can obtain the subscription information of the first communication device based on the identifier of the first communication device, and determine to provide computing services based on the second security algorithm to the first communication device based on the subscription information of the first communication device. For example, the first communication device sends the identifier of the first communication device to the second communication device through a fourth message, which may be the same as or different from the third message described above.

[0353] Optionally, the second communication device determines to provide computing services based on a second security algorithm to the first communication device. For example, the second communication device determines to provide homomorphic encryption services to the first communication device, wherein the homomorphic encryption service may be for the business data of the first communication device, and the second communication device supports data analysis and / or processing services in homomorphic ciphertext state.

[0354] This application does not limit the way in which the second communication device can obtain the subscription information of the first communication device based on the identifier of the first communication device. For example, the second communication device can search for the subscription information of the first communication device from other devices (such as UDM or AF) based on the identifier of the first communication device; or, for example, the second communication device locally stores the subscription information of the first communication device, and the second communication device can search for the subscription information of the first communication device locally based on the identifier of the first communication device.

[0355] Optionally, the second communication device determines to provide computing services based on the second security algorithm to the first communication device based on the first communication device's subscription information. This can be achieved by the second communication device determining the first communication device's security service policy based on the first communication device's subscription information, and then determining to provide computing services based on the second security algorithm to the first communication device according to the security service policy. For example, the second communication device determines whether to provide encrypted computing services to the first communication device based on the first communication device's subscription information and other pre-configured information (such as the first communication device's current computing power usage).

[0356] When a first session is established between the first communication device and the second communication device, the first message carrying N second keys may further include an identifier of the first session, so that the second communication device can establish an association between the N second keys and the identifier of the first session based on the identifier of the first session. Thus, when the identifier of the first session is included in the second message carrying the first ciphertext, the second communication device can determine the N second keys associated with the identifier of the first session based on the identifier of the first session.

[0357] Furthermore, after receiving the first ciphertext and N second keys, the second communication device can perform the following steps S1040 and S1050:

[0358] S1040, the second communication device obtains the third ciphertext.

[0359] The third ciphertext is obtained by encrypting the first ciphertext using the second security algorithm.

[0360] For example, the second communication device may obtain the third ciphertext by receiving the first ciphertext and encrypting it based on a second security algorithm to obtain the third ciphertext. For instance, the first ciphertext can be denoted as Enc. AES (m) or ciphertext c, taking the first security algorithm as a homomorphic encryption algorithm as an example, this first security algorithm is denoted as HE, and the encryption operation based on the second security algorithm can be represented as Enc. HE (), then the third ciphertext can be represented as Enc HE (Enc AES (m)), or Enc HE (c). This third ciphertext can be understood as a homomorphic AES encrypted ciphertext.

[0361] In this application, the second key is the first key that has been homomorphically encrypted, and the third ciphertext is the first ciphertext that has been homomorphically encrypted. Therefore, the second communication device can decrypt the third ciphertext based on N second keys. In the process of decrypting the third ciphertext based on N second keys, the second communication device does not need to decrypt the second key based on the homomorphic decryption key, nor does it need to decrypt the third ciphertext based on the homomorphic decryption key, because both the N second keys and the third ciphertext are in a homomorphic ciphertext state. Ciphertext in a homomorphic ciphertext state can be processed, so decrypting the third ciphertext based on N second keys is sufficient.

[0362] The method flow shown in Figure 10 may also include:

[0363] S1050, the second communication device decrypts the third ciphertext according to N second keys to obtain the second ciphertext.

[0364] The second ciphertext is the first data encrypted using a second security algorithm. For example, the second ciphertext can be denoted as Enc. HE (m).

[0365] For example, the process by which the second communication device decrypts the third ciphertext based on N second keys to obtain the second ciphertext includes the following steps:

[0366] Step 1.5: Determine the M block ciphertexts included in the third ciphertext, for example, Enc HE (c) Including Enc HE (c1.0), Enc HE (c2.0), Enc HE (c3.0)...Enc HE (cM.0).

[0367] Step 2.5: Based on the second key #n (e.g., Enc) among N second keys. HE (rkn)) Decrypting the block ciphertext Enc HE (c1.0) yields the intermediate ciphertext Enc. HE (c1.n-1), where n = 1, 2, ..., N-1.

[0368] For example, based on the second key #1 out of N second keys (e.g., Enc) HE (rk1) Decrypting the block ciphertext Enc HE (c1.0) yields the intermediate ciphertext Enc. HE (c1.1), based on the second key #2 among N second keys (e.g., Enc HE (rk2) Decrypting the block ciphertext Enc HE (c1.0) yields the intermediate ciphertext Enc. HE (c1.2), and so on.

[0369] Step 3.5: Based on the second key #N (e.g., Enc) among N second keys HE (rkN)) Decrypting the block ciphertext Enc HE (c1.N-1), yielding the group density

[0370] Furthermore, for other block ciphertexts Enc HE (c2.0), Enc HE (c3.0)...Enc HE (cM.0) can be obtained by referring to steps 1.5 to 3.5 above, respectively, to obtain the ciphertext Enc in the ciphertext state corresponding to the security algorithm. HE (m2), Enc HE (m3)...Enc HE (mM). Among them, Enc HE(m1), Enc HE (m2), Enc HE (m3)...and Enc HE (mM) is combined to obtain the decryption result of the third ciphertext based on N second key pairs by the second communication device, which is the aforementioned second ciphertext. This second ciphertext is in the ciphertext state corresponding to the second security algorithm. The second ciphertext is the same as the ciphertext obtained by encrypting the first data based on the second security algorithm, and can be denoted as Enc. HE (m).

[0371] Optionally, after the second communication device obtains the second ciphertext, it can also perform calculations on the second ciphertext to obtain a first calculation result. Then, the method flow shown in Figure 10 can further include:

[0372] S1060, the second communication device performs calculations on the second ciphertext based on the calculation key corresponding to the second security algorithm to obtain the first calculation result.

[0373] The second ciphertext supports computation in the ciphertext state corresponding to the second security algorithm. Therefore, the second communication device can directly perform computation on the second ciphertext based on the computation key corresponding to the second security algorithm, without needing to decrypt the second ciphertext based on the second security algorithm before or during the computation.

[0374] For example, the first data is a matrix, and the first calculation result can be the rank of that matrix under homomorphic ciphertext. For instance, the calculation based on the calculation key corresponding to the second security algorithm is denoted as Eval. HE (), the second ciphertext is denoted as Enc HE (m), the computation of the second ciphertext based on the computation key corresponding to the second security algorithm can be expressed as: Eval HE (Enc HE (m)), the first calculation result is the calculation result in the encrypted state.

[0375] Furthermore, the second communication device can also provide the first calculation result to the first communication device, and the method flow shown in Figure 10 can also include:

[0376] S1070, the second communication device sends the first calculation result to the first communication device, and correspondingly, the first communication device receives the first calculation result from the second communication device.

[0377] S1080, the first communication device decrypts the first calculation result based on the decryption key corresponding to the second security algorithm to obtain the second calculation result.

[0378] For example, the first communication device can obtain the second calculation result using a homomorphic decryption key. For instance, if the first data is a matrix, the first calculation result can be the rank of the matrix under homomorphic ciphertext, and the second calculation result can be the rank of the matrix.

[0379] In the communication method shown in Figure 10, based on the above technical solution, the first communication device can encrypt the first data based on N first keys to obtain the first ciphertext, and provide the first ciphertext to the second communication device. Additionally, N second keys generated based on the second security algorithm are also provided to the device (e.g., the second communication device) that decrypts the first ciphertext encrypted using the second security algorithm. Thus, the second communication device can encrypt the first ciphertext using the second security algorithm, so that the received N second keys can decrypt the first ciphertext processed by the second security algorithm. The ciphertext encrypted by the second security algorithm can be processed in its ciphertext state.

[0380] For example, the second security algorithm in this application can be understood as a homomorphic encryption algorithm. That is, in this technical solution, the first communication device does not need to provide the homomorphically encrypted ciphertext to the second communication device. Instead, the second communication device generates the homomorphically encrypted ciphertext itself and performs the subsequent decryption process, thereby reducing data transmission overhead while ensuring data security.

[0381] Additionally, as shown in Figure 9, the server is used to process the encrypted Enc... HE (c) The round key used for decryption is obtained by key expansion of the master key in the homomorphic ciphertext state, which has high computational complexity and prolongs the decryption process. The communication method shown in Figure 10 proposes to directly expand the master key in the plaintext state to obtain N first keys, and then encrypt the N first keys based on the second security algorithm to obtain N second keys, which are used to decrypt the third ciphertext. This helps to significantly reduce the complexity of key acquisition and improve decryption efficiency.

[0382] It should be understood that the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0383] It should also be understood that, unless otherwise specified or logically conflicting, the terminology and / or descriptions in the various embodiments of this application are consistent and can be referenced interchangeably. Furthermore, technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0384] The communication method provided in the embodiments of this application has been described in detail above with reference to Figure 10. The above communication method is mainly described from the perspective of interaction between various entities. It is understood that, in order to realize the above functions, the first communication device and the second communication device, etc., include hardware structures and / or software modules corresponding to the execution of each function.

[0385] Those skilled in the art will recognize that, based on the units and algorithm steps described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0386] The communication device provided in this application is described in detail below with reference to Figures 11 and 12. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for details not described in detail, please refer to the method embodiments above; for brevity, some details are omitted.

[0387] This application embodiment can divide the first communication device and the second communication device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the division of each functional module according to each function as an example.

[0388] Figure 11 is a schematic block diagram of a communication device 10 provided in an embodiment of this application. The device 10 includes a transceiver unit 11 and a processing unit 12. The transceiver unit 11 can implement corresponding communication functions, and the processing unit 12 is used for data processing. In other words, the transceiver unit 11 is used to perform operations related to receiving and sending, and the processing unit 12 is used to perform other operations besides receiving and sending. The transceiver unit 11 can also be referred to as a communication interface or a communication unit.

[0389] Optionally, the device 10 may further include a storage unit 13, which may be used to store instructions and / or data. The processing unit 12 may read the instructions and / or data in the storage unit so that the device can perform the operation of the device in the aforementioned method embodiments.

[0390] In one design, the device 10 may correspond to the first communication device in the above method embodiments, or to a component of the first communication device (such as a chip).

[0391] The device 10 can implement the steps or processes corresponding to those performed by the first communication device in the above method embodiment. The transceiver unit 11 can be used to perform the transceiver-related operations of the first communication device in the above method embodiment, and the processing unit 12 can be used to perform the processing-related operations of the first communication device in the above method embodiment.

[0392] In one possible implementation, processing unit 12 is used to encrypt first data based on N first keys to obtain first ciphertext. Processing unit 12 is also used to encrypt each of the N first keys based on a second security algorithm to obtain N second keys. Transceiver unit 11 is used to send the aforementioned first ciphertext and N second keys to a second communication device.

[0393] When the device 10 is used to execute the method in FIG10, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1003, S1004, S1030 and S1070; the processing unit 12 can be used to execute the processing steps in the method, such as steps S1103, S1010, S1020 and S1080.

[0394] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0395] In another design, the device 10 may correspond to the second communication device in the above method embodiment, or to a component of the second communication device (such as a chip).

[0396] The device 10 can implement the steps or processes corresponding to those performed by the second communication device in the above method embodiments. The transceiver unit 11 can be used to perform transceiver-related operations of the second communication device in the above method embodiments, and the processing unit 12 can be used to perform processing-related operations of the second communication device in the above method embodiments.

[0397] In one possible implementation, transceiver unit 11 is configured to acquire a third ciphertext, which is obtained by encrypting a first ciphertext using a second security algorithm. The first ciphertext is obtained by encrypting first data using N first keys corresponding to the first security algorithm, where N is an integer greater than 1. The ciphertext encrypted using the second security algorithm can be processed in its ciphertext state. Transceiver unit 11 is further configured to receive N second keys, which are obtained by encrypting the N first keys using the second security algorithm. Processing unit 12 is configured to decrypt the third ciphertext using the N second keys to obtain a second ciphertext in its ciphertext state corresponding to the second security algorithm.

[0398] When the device 10 is used to execute the method in FIG10, the transceiver unit 11 can be used to execute the steps of transmitting and receiving information in the method, such as steps S1003, S1004, S1030 and S1070; the processing unit 12 can be used to execute the processing steps in the method, such as steps S1103, S1040, S1050 and S1060.

[0399] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0400] It should also be understood that the device 10 here is embodied in the form of a functional unit. The term "unit" here can refer to an application-specific integrated circuit (ASIC), electronic circuitry, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, integrated logic circuitry, and / or other suitable components supporting the described functions. In an alternative example, those skilled in the art will understand that device 10 may specifically be a mobility management network element in the above embodiments, and may be used to execute the various processes and / or steps corresponding to the mobility management network element in the above method embodiments; or, device 10 may specifically be a terminal device in the above embodiments, and may be used to execute the various processes and / or steps corresponding to the terminal device in the above method embodiments. To avoid repetition, further details are omitted here.

[0401] The apparatus 10 of each of the above-described schemes has the function of implementing the corresponding steps performed by the entities (such as the first communication device and the security network element) in the above-described methods. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-described functions; for example, the transceiver unit can be replaced by a transceiver (for example, the transmitting unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as processing units, can be replaced by processors, which respectively execute the transceiver operations and related processing operations in each method embodiment.

[0402] In addition, the transceiver unit 11 can also be a transceiver circuit (for example, it may include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit.

[0403] Figure 13 is a schematic diagram of another communication device 20 provided in an embodiment of this application. The device 20 includes a processor 21, which is used to execute computer programs or instructions stored in a memory 22, or to read data / signaling stored in the memory 22, to perform the methods in the above-described method embodiments. Optionally, there may be one or more processors 21.

[0404] Optionally, as shown in FIG13, the device 20 further includes a memory 22 for storing computer programs or instructions and / or data. The memory 22 may be integrated with the processor 21 or may be disposed separately. Optionally, there may be one or more memories 22.

[0405] Optionally, as shown in FIG13, the device 20 further includes a transceiver 23 for receiving and / or transmitting signals. For example, the processor 21 is used to control the transceiver 23 to receive and / or transmit signals.

[0406] As one option, the device 20 is used to implement the operations performed by the first communication device and the second communication device in the various method embodiments described above.

[0407] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or it can be one or more combinations of other general-purpose processors, digital signal processors (DSPs), microprocessor units (MPUs), microcontroller units (MCUs), graphics processing units (GPUs), field-programmable gate arrays (FPGAs), artificial intelligence processors (AI processors), or neural processing units (NPUs); or, the processor mentioned in the embodiments of this application can be an ASIC or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0408] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be cache or random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0409] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.

[0410] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0411] This application also provides a chip system (or processing system) including logic circuits and input / output interfaces.

[0412] The logic circuit can be a processing circuit in the chip system. The logic circuit can be coupled to a memory cell, calling instructions from the memory cell, enabling the chip system to implement the methods and functions of the embodiments of this application. The input / output interface can be an input / output circuit in the chip system, outputting processed information or inputting data or signaling information to be processed into the chip system for processing.

[0413] As one approach, the chip system is used to implement the operations performed by the first communication device and the second communication device in the various method embodiments described above.

[0414] For example, the logic circuit is used to implement the processing-related operations performed by the first communication device and the second communication device in the above method embodiments; the input / output interface is used to implement the sending and / or receiving-related operations performed by the first communication device and the second communication device in the above method embodiments.

[0415] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by the first communication device and the second communication device in the above-described method embodiments.

[0416] For example, when the computer program is executed by the computer, it enables the computer to implement the methods executed by the first communication device and the second communication device in the various embodiments of the above methods.

[0417] This application also provides a computer program product comprising instructions which, when executed by a computer, implement the methods performed by the first communication device and the second communication device in the above-described method embodiments.

[0418] This application also provides a communication system, including the aforementioned first communication device. Optionally, the communication system further includes the aforementioned second communication device.

[0419] The explanations and beneficial effects of the relevant contents in any of the devices provided above can be found in the corresponding method embodiments provided above, and will not be repeated here.

[0420] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0421] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0422] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of the apparatus or units may be electrical, mechanical, or other forms.

[0423] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0424] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0425] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0426] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method, characterized in that, The method includes: The first data is encrypted using N first keys corresponding to the first security algorithm to obtain the first ciphertext, where N is an integer greater than 1; The N first keys are encrypted using the second security algorithm to obtain N second keys. The N second keys support the decryption of the ciphertext obtained based on the first security algorithm in the ciphertext state corresponding to the second security algorithm. Send the first ciphertext and the N second keys.

2. The method according to claim 1, characterized in that, The N first keys are encrypted using the second security algorithm to obtain N second keys, including: Based on the second security algorithm, the N first keys are encrypted respectively to obtain N third keys; The N second keys are determined based on the N third keys.

3. The method according to claim 1 or 2, characterized in that, The first ciphertext comprises M block ciphertexts, where M is an integer greater than 1. Sending the first ciphertext and the N second keys includes: Send the first ciphertext of the M ciphertext blocks; The N second keys are sent sequentially; After the first block of ciphertext is decrypted, the remaining blocks of ciphertexts (excluding the first block of ciphertext) from the M blocks of ciphertexts are sent sequentially.

4. The method according to any one of claims 1 to 3, characterized in that, Sending the N second keys includes: If the first security algorithm is a non-shared security algorithm, then send the N second keys.

5. The method according to any one of claims 1 to 4, characterized in that, Sending the N second keys includes: Send a first message, which includes the N second keys and N key identifiers, wherein the N key identifiers are used to identify the N second keys respectively.

6. The method according to any one of claims 1 to 5, characterized in that, Sending the first ciphertext includes: A second message is sent, the second message including the first ciphertext and an identifier of the first session, the first session being used to transmit at least one ciphertext, the first ciphertext being one of the at least one ciphertext. The identifier of the first session is associated with the N second keys.

7. The method according to claim 6, characterized in that, The first session includes an artificial intelligence service session.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Send a first indication message and / or a second indication message, wherein the first indication message is used to indicate the length of the first key, and the second indication message is used to indicate the first security algorithm and / or the second security algorithm.

9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Receive a first calculation result, wherein the first calculation result is in the ciphertext state corresponding to the second security algorithm; The first calculation result is decrypted using the decryption key corresponding to the second security algorithm to obtain the second calculation result.

10. The method according to any one of claims 1 to 9, characterized in that, The method is executed by an artificial intelligence user device.

11. A communication method, characterized in that, The method includes: Obtain the third ciphertext, which is obtained by encrypting the first ciphertext based on the second security algorithm. The first ciphertext is obtained by encrypting the first data based on N first keys corresponding to the first security algorithm, where N is an integer greater than 1. Receive N second keys, wherein the N second keys are obtained by encrypting the N first keys respectively based on the second security algorithm; The third ciphertext is decrypted using the N second keys to obtain the second ciphertext, which is in the ciphertext state corresponding to the second security algorithm. During the decryption process, the N second keys and the third ciphertext are in the ciphertext state corresponding to the second security algorithm.

12. The method according to claim 11, characterized in that, The first ciphertext comprises M block ciphertexts, where M is an integer greater than 1. The method further includes: Receive the first ciphertext of the M ciphertext blocks; The receipt of N second keys includes: Receive the N second keys in sequence; After the first block of ciphertext has been decrypted, the method further includes: Send a message indicating that the first block of ciphertext has been decrypted; The M ciphertext blocks, excluding the first ciphertext block, are received sequentially.

13. The method according to claim 11 or 12, characterized in that, The receipt of N second keys includes: Receive a first message, which includes the N second keys and N key identifiers, wherein the N key identifiers are used to identify the N second keys respectively.

14. The method according to any one of claims 11 to 13, characterized in that, The acquisition of the third ciphertext includes: Receive the first ciphertext; The first ciphertext is encrypted using the second security algorithm to obtain the third ciphertext.

15. The method according to claim 14, characterized in that, Receiving the first ciphertext includes: Receive a second message, the second message including the first ciphertext and an identifier of a first session, the first session being used to transmit at least one ciphertext, the first ciphertext being one of the at least one ciphertext; The method further includes: The N second keys are determined based on the identifier of the first session.

16. The method according to claim 15, characterized in that, The receipt of N second keys includes: Receive the N second keys and the identifier of the first session, wherein the identifier of the first session is associated with the N second keys; Store the association between the N second keys and the identifier of the first session; The step of determining the N second keys based on the identifier of the first session includes: Based on the identifier of the first session and the association relationship, the N second keys are determined.

17. The method according to claim 15 or 16, characterized in that, The method further includes: Receive a third message, the third message being used to request the establishment of the first session; In response to the third message, an identifier for the first session is assigned; Send the identifier of the first session.

18. The method according to any one of claims 15 to 17, characterized in that, The first session includes an artificial intelligence service session.

19. The method according to any one of claims 11 to 18, characterized in that, The method further includes: Receive a fourth message, the fourth message including the identifier of the first communication device; Obtain the subscription information of the first communication device based on the identifier of the first communication device; Based on the signed information, it is determined that the first communication device will be provided with computing services based on the second security algorithm.

20. The method according to claim 19, characterized in that, The step of determining to provide computing services based on the second security algorithm to the first communication device based on the subscription information includes: Based on the subscription information, a security service policy for the first communication device is determined, wherein the security service policy indicates that computing services based on the second security algorithm are permitted for the first communication device; According to the security service policy, the first communication device is provided with computing services based on the second security algorithm.

21. The method according to any one of claims 11 to 20, characterized in that, The method further includes: Receive a first indication information and / or a second indication information, wherein the first indication information is used to indicate the length of the first key, and the second indication information is used to indicate the first security algorithm and / or the second security algorithm.

22. The method according to any one of claims 11 to 21, characterized in that, The method further includes: The second ciphertext is calculated based on the calculation key corresponding to the second security algorithm to obtain the first calculation result; Send the first calculation result.

23. The method according to any one of claims 11 to 22, characterized in that, The method is executed by an artificial intelligence agent device.

24. A communication device, characterized in that, include: One or more modules for performing the method as described in any one of claims 1 to 10, or one or more modules for performing the method as described in any one of claims 11 to 23.

25. A communication device, characterized in that, It includes at least one processor for executing a computer program or instructions to cause the method as described in any one of claims 1 to 10 to be performed, or to cause the method as described in any one of claims 11 to 23 to be performed.

26. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program or instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 23.

27. A computer program product, characterized in that, It includes a computer program or instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 23.