WO2014071585A1 - Method and device for obtaining public key - Google Patents
Method and device for obtaining public key Download PDFInfo
- Publication number
- WO2014071585A1 WO2014071585A1 PCT/CN2012/084291 CN2012084291W WO2014071585A1 WO 2014071585 A1 WO2014071585 A1 WO 2014071585A1 CN 2012084291 W CN2012084291 W CN 2012084291W WO 2014071585 A1 WO2014071585 A1 WO 2014071585A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- local
- certificate
- cbe
- cross
- public key
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 118
- 238000004891 communication Methods 0.000 claims description 28
- 238000012795 verification Methods 0.000 claims description 28
- 238000010586 diagram Methods 0.000 description 44
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 238000011022 operating instruction Methods 0.000 description 2
- 230000008520 organization Effects 0.000 description 2
- 238000012545 processing Methods 0.000 description 2
- 238000006467 substitution reaction Methods 0.000 description 2
- 238000006424 Flood reaction Methods 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000000295 complement effect Effects 0.000 description 1
- 238000004880 explosion Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 238000004321 preservation Methods 0.000 description 1
- 238000011160 research Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/90—Services for handling of emergency or hazardous situations, e.g. earthquake and tsunami warning systems [ETWS]
Definitions
- the invention belongs to the field of communications, and in particular relates to a method and a device for acquiring a public key.
- PWS Public Warning System
- the PWS service is provided to the user by the telecommunications carrier (the content of which can be provided by the alert information provider) Provided).
- the operator or the alarm information supply department When certain events occur, the operator or the alarm information supply department generates an alarm message. To the operator. Operators use their network to send alerts to users. Since the release of such messages as PWS will likely cause large-scale panic, the security requirements are also high. According to PWS Security requirements, security mechanisms should prevent false alarm notifications; the integrity of alarm notifications should be protected; the source of alarm notifications should be identified.
- PWS public alarm security is a research hotspot in the SA3 organization of the 3GPP standards organization, and different equipment vendors propose different security solutions.
- the SA3 standard discussed the certificate-based programming scenario at the 67th meeting, and the specific programme was discussed at the 68th meeting, and the programme was discussed through a PWS called TR33.869.
- This implicit certificate Implicit certificate is specifically planned to deploy several or more global certification authority centers on a global scale ( Certification Authority, CA) is the security initial node of PWS.
- User User Equipment , UE
- the public keys of these global CAs are pre-configured in ).
- the cell broadcast entity periodically obtains an Implicit certificate from a global CA and will Implicit Certificate is transmitted as a secure part of the PWS message.
- the public key of the cell broadcast entity is the public key of the CA and Implicit certificate Calculated. Thereby the UE verifies the signature of the PWS message by the public key of the cell broadcast entity.
- Step1 Deploy multiple global CAs globally and configure the public keys of these CAs in the UE;
- Step2 Cell Broadcast Entity (CBE) ) Periodically obtain an Implicit Certificate from a global CA, that is, the CA issues an Implicit Certificate for the CBE.
- CBE Cell Broadcast Entity
- Step3 Public alarm event occurs, CBE passes the cell broadcast center (Cell Broadcast Centre , CBC) Broadcasts a PWS message to the alarm location.
- the PWS message contains the PWS message and the security part.
- the security section specifically includes the CBE's signature of the PWS message and the CA. Implicit Certificate issued to CBE.
- Implicit certificate computes the CBE's public key (Signer's Public key ) and then validates the PWS via the CBE's public key The signature of the message to identify whether the received PWS message is a legitimate public alert message.
- Implicit Certificate-based approach is the deployment of a global CA on the UE.
- Public key when the UE receives a message containing a PWS message and a secure message, it calculates the CBE using the pre-configured CA public key and the Implicit Certificate certificate. The public key in turn verifies the signature of the PWS message.
- a scenario that exposes the problem of this scenario: when a UE roams into such a network, no global CA is deployed in the network. Or, for some reason, a carrier network in a country uses its own deployed CAx, which is not in the global CA list. The UE will not pre-configure information to the CAx (CAx) Public key) This will cause the UE to fail to verify PWS messages after roaming to receive PWS messages locally.
- CAx CAx
- An object of the embodiments of the present invention is to provide a method for obtaining a public key, which solves how to make a UE if it is not configured locally.
- the CAx public key how to implement the UE to verify the PWS message in this scenario.
- a method for obtaining a public key comprising:
- the network element receives the global authentication authority CA list or the determined CA information reported by the user;
- the network element sends the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user calculates the office according to the cross-certificate or the implicit certificate.
- Local CA The public key or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system PWS delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. Message.
- the method further includes:
- the network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server.
- User causing the user to calculate the local according to the cross certificate or implicit certificate
- the method further includes:
- the network element When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, the network element entity in the GSM or GPRS network is MSG or SGSN.
- a second aspect is a method for obtaining a public key, the method comprising:
- the user reports the global CA list or the determined CA information to the network element.
- the user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and sends the PWS to the user according to the cross certificate or the implicit certificate to the local CBE.
- the message is verified.
- the user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and sends the PWS to the user according to the cross certificate or the implicit certificate to the local CBE.
- the message is verified as follows:
- the public key of the local CA is calculated according to the calculated public key of the local CA
- the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
- the signature of the PWS message is
- the user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and sends the PWS to the user according to the cross certificate or the implicit certificate to the local CBE.
- the message is verified as follows:
- the method further includes:
- the implicit certificate in the issued PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- a third aspect a network element, where the network element includes:
- a receiving unit configured to receive a global certification authority CA list or determined CA information reported by the user
- An obtaining unit configured to: when the local CA is not in the global CA list or the local CA is not the determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- a first sending unit configured to send, by the network element, a cross-certificate or an implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local
- the public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- the network element further includes a sending unit, where the sending unit includes:
- the network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server.
- User causing the user to calculate the local according to the cross certificate or implicit certificate
- the network element further includes a second sending unit, where the second lower unit includes:
- the network element When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, the network element entity in the GSM or GPRS network is MSG or SGSN.
- a fourth aspect a terminal device, where the terminal device includes:
- An information sending unit configured to report, by the user, the global CA list or the determined CA information to the network element;
- Receiving a verification unit configured to receive, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and send the local CBE to the local CBE according to the cross certificate or the implicit certificate users
- the PWS message is verified.
- the receiving and verifying unit includes a first receiving and verifying unit, and the first receiving and verifying unit includes:
- the public key of the local CA is calculated according to the calculated public key of the local CA
- the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
- the signature of the PWS message is
- the receiving verification unit includes a second receiving verification unit, and the second receiving verification unit includes:
- the terminal device further includes a third receiving verification unit, where the third receiving verification unit includes:
- the third receiving verification unit includes:
- the implicit certificate in the issued PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- a fifth aspect a network element, where the network element includes:
- a receiving unit configured to receive a global certification authority CA list or determined CA information reported by the user
- An obtaining unit configured to: when the local CA is not in the global CA list or the local CA is not the determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- a first sending unit configured to send, by the network element, a cross-certificate or an implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local
- the public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- the network element includes a processor, a communication interface, a memory, and a bus;
- the processor, the communication interface, and the memory complete communication with each other through the bus;
- the communication interface is configured to communicate with other Wangyu devices
- the processor is configured to execute a program
- the memory is configured to store a program
- the program is used to receive the global certification authority CA list or the determined CA information reported by the user; when the local CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists when the global CA list or the local CA is not the determined CA; or obtaining the determined CA a cross-certificate or an implicit certificate; the network element will send the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local
- the public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- the network element further includes a sending unit, where the sending unit includes:
- the network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server.
- User causing the user to calculate the local according to the cross certificate or implicit certificate
- the network element Also included is a second delivery unit, the second lower unit comprising:
- the network element When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, the network element entity in the GSM or GPRS network is MSG or SGSN.
- a sixth aspect a terminal device, where the terminal device includes:
- An information sending unit configured to report, by the user, the global CA list or the determined CA information to the network element;
- Receiving a verification unit configured to receive, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and send the local CBE to the local CBE according to the cross certificate or the implicit certificate users
- the PWS message is verified.
- the network element includes a processor, a communication interface, a memory, and a bus;
- the processor, the communication interface, and the memory complete communication with each other through the bus;
- the communication interface is configured to communicate with other network elements
- the processor is configured to execute a program
- the memory is configured to store a program
- the program is used by the user to list the global CA or determine the CA.
- the information is reported to the network element; the user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and the local CBE is performed according to the cross certificate or the implicit certificate. Sent to the user The PWS message is verified.
- the receiving and verifying unit includes a first receiving and verifying unit, and the first receiving and verifying unit includes:
- the public key of the local CA is calculated according to the calculated public key of the local CA
- the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
- the signature of the PWS message is
- the receiving verification unit includes a second receiving verification unit, and the second receiving verification unit includes:
- the terminal device further includes a third receiving verification unit, where the third receiving verification unit includes:
- the third receiving verification unit includes:
- the implicit certificate in the issued PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local Obtaining, by the MME, a cross-certificate of any one of the global CA lists, or a cross-certificate of the determined CA, according to the global list or the determined CA, the local MME
- the obtained cross-certificate is delivered to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
- the cross-certificate sent to the local NE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 1 is a flowchart of a method for obtaining a public key according to Embodiment 1 of the present invention
- FIG. 2 is a flowchart of a method for obtaining a public key according to Embodiment 2 of the present invention
- FIG. 3 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention.
- FIG. 4 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention.
- FIG. 5 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention.
- FIG. 6 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention.
- FIG. 7 is a flowchart of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 8 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 9 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 10 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 11 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 12 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 13 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- FIG. 15 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 16 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 17 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 18 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 19 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 20 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 21 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 22 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention.
- FIG. 24 is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
- FIG. 25 is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
- 26 is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
- FIG. 27 is a schematic diagram of a method for obtaining a public key according to Embodiment 6 of the present invention.
- FIG. 28 is a structural diagram of a device of a network element according to Embodiment 7 of the present invention.
- FIG. 29 is a structural diagram of a device of a network element according to Embodiment 8 of the present invention.
- FIG. 30 is a structural diagram of a device of a network element according to Embodiment 9 of the present invention.
- FIG. 31 is a structural diagram of a device of a network element according to Embodiment 10 of the present invention.
- FIG. 32 is a structural diagram of a device of a network element according to Embodiment 11 of the present invention.
- FIG. 33 is a structural diagram of a device of a terminal device according to Embodiment 12 of the present invention.
- FIG. 34 is a structural diagram of a device of a network element according to Embodiment 13 of the present invention.
- 35 is a structural diagram of a device of a terminal device according to Embodiment 14 of the present invention.
- FIG. 1 is a flowchart of a method for obtaining a public key according to Embodiment 1 of the present invention. As shown in Figure 1:
- Step 101 The network element receives the global authentication and authorization center CA list or the determined CA information reported by the user.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
- CAx deploys its own network CA for the user roaming network, which is not within the planned global CA scope; CA1 belongs to the global CA scope and is one of the user-preconfigured global CAs.
- CAx If there is no mutual trust between the CAs, CAx needs to go to CA1. Establish a mutual trust relationship and obtain a cross-certificate. Otherwise, if the mutual trust relationship cannot be established, CA1 will not be able to verify the PWS message delivered by the local CBE, and cannot inform the user of PWS. Security, at this time, the user will decide whether to continue the PWS alarm message sent by the local CBE.
- Step 102 When the local CA is not in the global CA list or the local CA is not the determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- the optional user can list the global CA or determine the CA.
- the information is reported to the roaming network, that is, the network element of the local network, so that the local network element determines, according to the global CA list or the determined CA information, whether the local network pre-stores any one of the global CA lists.
- Cross-certificate or implicit certificate of the CA or whether the local network pre-stores the determined CA A cross-certificate or an implicit certificate in the message. If the local network element is saved, the local network element is directly sent to the user; if the local network element is not stored, the local network element obtains a cross certificate of any one of the global lists or obtains the determined CA. Cross certificate.
- Step 103 The network element sends the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate or the implicit certificate obtained by the network element to the user, so that the user calculates the office according to the cross-certificate or the implicit certificate.
- Local CA The public key or the public key of the local cell broadcast entity CBE, and enable the user to verify the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- the information of the cross-certificate may be information such as the address or information of the cross-certificate, and the information of the cross-certificate enables the user to obtain the cross-certificate according to the information of the cross-certificate.
- the network element sends the obtained cross-certificate or the obtained cross-certificate information to the user
- the user corresponds to the cross-certificate and the cross-certificate corresponding to the global
- the public key of a specific CA in the CA list the public key of the local CA is calculated, and the local key is calculated according to the public key of the local CA and the implicit certificate in the PWS message sent to the user by the local CBE.
- the public key of the CBE the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE, thereby identifying the received PWS Whether the message is a legitimate public alarm message.
- the information of the implicit certificate may be information such as an address or information of an implicit certificate, and the information of the implicit certificate enables the user to obtain an implicit certificate according to the information of the implicit certificate.
- the network element sends the obtained implicit certificate or the information for obtaining the implicit certificate to the user
- the user corresponds to the global certificate corresponding to the implicit certificate and the implicit certificate.
- the public key of a specific CA in the CA list the public key of the local CBE is calculated, and the PWS message sent by the local CBE to the user is verified according to the public key of the local CBE, thereby identifying the received Whether the PWS message is a legitimate public alarm message.
- the cross-certificate or the implicit certificate obtained by the network element may be selected to send the information such as the link or address of the cross-certificate, or the link or address to which the implicit certificate is issued.
- the method further includes:
- the network element sends the obtained cross-certificate or implicit certificate to the application server, where the cross-certificate or the implicit certificate is used by the application server, or the application server uses the cross-certificate or the implicit certificate.
- the information is sent to the user, so that the user downloads a cross certificate or an implicit certificate to the corresponding download server, and calculates the local area according to the cross certificate or the implicit certificate.
- the public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- the application server sends the information of the cross-certificate or the implicit certificate to the user, where the information includes, but is not limited to, a link or address of the information of the cross-certificate or the implicit certificate.
- the method further includes:
- the network element When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA by a user. And obtaining, by the local network element, a cross certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or determining the CA
- the cross-certificate or the implicit certificate the network element sends the obtained cross-certificate or the implicit certificate to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, by A cross-certificate or an implicit certificate that is sent to the local NE by any CA in the CA list, and the public key of the local network element CBE is calculated, so as to verify the PWS sent to the user by the local CBE.
- the purpose of the message is obtaining, by the local network element, a cross certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or determining the CA
- FIG. 2 is a flowchart of a method for obtaining a public key according to Embodiment 2 of the present invention.
- Step 201 The local core network entity receives a global authentication authorization center CA list or a determined CA reported by the user. Information
- the local core network entity receives the global CA list reported by the user, referring to step 301 and FIG. 4 of FIG. Steps 401.
- the local core network entity receives the determined CA information reported by the user, referring to step 501 and FIG. 6 of FIG. Steps 601.
- Step 202 When the local CA is not in the global CA list or is not a determined CA And obtaining, by the local core network entity, a cross certificate of any one of the global CA lists or a cross certificate of the determined CA;
- the local core network entity receives a global CA list reported by the user, when the local CA is not in the global CA.
- the list is in the list, and when the cross-certificate of any one of the global CA lists is stored in the local core network entity, the any one of the local core network entities stored is directly obtained from the local core network entity.
- CA's cross-certificate Refer to step 302 of Figure 3.
- any CA is selected from the global CA list, and the local core network entity obtains the cross-certificate of the selected one of the CAs.
- the local core network entity receives the determined CA information reported by the user, when the local MME stores the determined When the CA cross-certifies, the cross-certificate of the determined CA stored by the local core network entity is obtained directly from the local core network entity. Refer to step 502 of Figure 5.
- the local core network entity does not store the cross-certificate of the determined CA
- the determined CA is obtained. Obtaining the cross-certificate of the determined CA. Refer to step 602 and step 603 of Figure 6.
- Step 203 the local core network entity sends the obtained cross-certificate, or the information of the cross-certificate obtained by the local core network entity to the user, so that the user calculates the local CA according to the cross-certificate The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA.
- Step 404 step 503 of FIG. 5, step 604 of FIG. 6;
- the local core network entity sends the obtained information of the cross-certificate to the user.
- the local core network entity sends the obtained information of the cross-certificate to the user.
- Step 404 of Figure 4 step 503 of Figure 5, and step 604 of Figure 6.
- the method further includes:
- the core network entity sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the information of the cross-certificate to the user, so that the user obtains the cross-certificate and according to the Cross certificate calculation for the local
- the public key of the CA and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- the core network entities in this manual use the MME in the LTE network as an example.
- step 301 the MME receives a global CA list reported by the user
- Step 302 the MME checks the received global CA list and the local MME. Whether the preservation is consistent;
- Step 303 If the MME is consistent, the MME sends the locally saved cross certificate or cross certificate information.
- Step 304 If the MME is consistent, the MME sends the locally saved cross certificate to the application server.
- Step 305 The application server sends the cross-certificate or cross-certificate information to the user.
- step 401 the MME receives a global CA list reported by the user
- Step 402 The MME checks whether the received CA list is consistent with that saved by the local MME.
- Step 403 If not, the MME obtains a cross-certificate of any one of the CAs in the CA list;
- Step 404 The MME sends a cross certificate or cross information to the user.
- Step 405 The MME sends the obtained cross certificate to the application server.
- Step 406 The application server delivers the information of the cross certificate or the cross certificate to the user.
- step 501 the MME obtains the determined CA information sent by the user.
- Step 502 The MME checks whether a cross certificate of the determined CA is saved locally.
- Step 503 if yes, the MME sends the locally saved cross certificate or cross certificate information
- Step 504 if yes, the cross certificate issued by the local MME is sent to the application server;
- Step 505 The application server delivers the cross certificate or cross certificate information to the user.
- step 601 the user sends the determined CA information to the MME;
- Step 602 The MME checks whether a cross certificate of the determined CA is saved locally.
- Step 603 If not saved, the MME obtains the cross certificate of the determined CA.
- Step 604 The MME sends the cross-certificate or cross-certificate information to the user.
- Step 605 The MME sends the obtained cross certificate to the application server.
- Step 606 The application server sends the information of the cross certificate or the cross certificate to the user.
- An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local Obtaining, by the MME, a cross-certificate of any one of the global CA lists, or a cross-certificate of the determined CA, according to the global list or the determined CA, the local MME
- the obtained cross-certificate is delivered to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
- the cross-certificate sent to the local NE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 7 is a flowchart of a method for obtaining a public key according to Embodiment 3 of the present invention. As shown in Figure 7:
- Step 701 The local CBE receives the global authentication and authorization center CA delivered by the local core network entity. List or determined CA information.
- the local CBE receives a global CA list forwarded by the local core network entity, and the core network entity will be global
- the CA list is forwarded directly to the local CBE.
- the core network entities in this manual use the MME in the LTE network as an example.
- the MME selects any CA from the global CA list, and selects any one of the selected CAs. Issued to the local CBE. Refer specifically to steps 1001 and 1002 of Figure 10 and steps 1101 and 1102 of Figure 11.
- the local CBE receives the determined CA information forwarded by the local MME.
- Steps 1201 and steps and steps 1301 and 1302 of Figure 13 are the steps 1201 and steps 1201 and 1302 of Figure 13.
- Step 702 When the local CA is not in the CA list or the local CA is not the determined CA And obtaining, by the local CBE, a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- the implicit certificate of any CA in the list is obtained directly from the local CBE. Refer to step 803 of Figure 8 for details.
- the local CBE when the local CBE obtains the global CA list, and when the local CBE does not store the global When an implicit certificate of any one of the CAs in the CA list is selected, the local CBE selects any CA from the global CA list and obtains any CA selected. Cross certificate. Refer specifically to steps 903 and 904 of Figure 9.
- the local CBE obtains any one of the CAs selected by the MME from the global CA list
- the local CBE stores an implicit certificate of any one of the CAs selected by the MME
- the implicit certificate of the any one of the CAs is directly obtained from the local CBE.
- the local CBE obtains any one of the CAs selected by the MME from the global CA list
- the local CBE does not store the implicit certificate of any one of the CAs selected by the MME
- the cross-certificate of the any one of the CAs is obtained in the local CBE.
- the implicit certificate of the determined CA is obtained directly from the local CBE. Refer specifically to step 1203 of Figure 12.
- the local CBE receives the determined CA information forwarded by the local MME, and when the local CBE When the implicit certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer to step 1303 and step 1304 of Figure 13 for details.
- Step 703 the cross certificate or implicit certificate that the local CBE will acquire, or the CBE And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate.
- the public key and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
- the local CBE sends the obtained cross-certificate or the implicit certificate to the user.
- step 804 of FIG. Step 905 of Fig. 9 step 1004 of Fig. 10, step 1105 of Fig. 11, step 1204 of Fig. 12, and step 1305 of Fig. 13.
- the local CBE sends the obtained cross-certificate information or the implicit certificate to the user.
- step 905 of FIG. 9 step 1004 of FIG. 10, step 1105 of FIG. 11, step 1204 of FIG. 12, and step 1305 of FIG. .
- the CBE can obtain any CA selected by the CBC from the global CA list.
- the specific method is similar.
- the method further includes:
- the CBE Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user.
- Causing a user to calculate the local based on the cross-certificate The public key of the CA, or causing the user to calculate the public key of the local CBE according to the implicit certificate, and causing the user to verify the local CBE according to the public key of the local CA or the public key of the local CBE
- the user's public alarm system PWS message is delivered. Referring specifically to step 805 and step 806 of FIG. 8, step 906 and step 907 of FIG. 9, step 1005 of FIG. And step 1006, step 1106 and step 1107 of FIG. 11, step 1205 and step 1206 of FIG. 12, step 1306 and step of FIG. 1307.
- FIG 8, Figure 9, Figure 10, Figure 11, Figure 12, Figure 13 A schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention.
- the CBE may also obtain any CA selected by the CBC from the global CA list. The specific method is similar.
- step 801 the local MME receives a global CA list sent by the user.
- Step 802 the local CBE receives the global CA forwarded by the local MME received by the CBC List
- Step 803 the local CBE determines whether to save any CA in the global CA list. Implicit certificate
- Step 804 if yes, the local CBE sends the information of the implicit certificate or the implicit certificate to the user;
- Step 805 if yes, the local CBE sends the obtained implicit certificate to the application server;
- Step 806 The application server sends the information of the implicit certificate or the implicit certificate to the user.
- step 901 the local MME receives a global CA list sent by the user;
- Step 902 The local CBE forwards the global CA forwarded by the local MME received by the CBC. List
- Step 903 the local CBE determines whether to save any CA in the global CA list. Implicit certificate
- Step 904 If the local CBE does not save the cross-certificate of any one of the global CA lists, obtain any one. CA's cross-certificate;
- Step 905 if yes, the cross-certificate or the cross-certificate is delivered to the user;
- Step 906 if yes, the obtained cross certificate is sent to the application server;
- Step 907 The application server delivers the information of the cross certificate or the cross certificate to the user.
- step 1001 the MME receives a global CA list sent by a user
- Step 1002 the CBE receives the MME received by the CBC from a global CA. Any CA selected in the list;
- Step 1003 The local CBE determines whether to save the implicit certificate of any CA that is delivered;
- Step 1004 if yes, the local CBE sends the information of the implicit certificate or the implicit certificate to the user;
- Step 1005 The local CBE sends the obtained implicit certificate to the application server.
- Step 1006 The application server sends the information of the implicit certificate or the implicit certificate to the user.
- step 1101 the MME receives a global CA list sent by the user
- Step 1102 The local CBE receives an MME randomly selected from the global CA list received by the CBC. CA ;
- Step 1103 The local CBE determines whether to save the implicit certificate of any CA that is delivered;
- Step 1104 If not saved, the local CBE obtains the cross-certificate of the any one of the CAs;
- Step 1105 The local CBE sends the cross-certificate or cross-certificate information to the user.
- Step 1106 The local CBE sends the obtained cross certificate to the application server.
- Step 1107 The application server delivers the cross certificate or cross certificate information to the user.
- step 1201 the MME receives the determined CA information sent by the user.
- Step 1202 The local CBE receives the determined CA information forwarded by the MME.
- Step 1203 The local CBE determines whether to save the implicit certificate of the forwarded determined CA.
- Step 1204 if yes, sending the information of the implicit certificate or the implicit certificate to the user;
- Step 1205 The local CBE sends the obtained implicit certificate to the application server.
- Step 1206 The application server sends the information of the implicit certificate or the implicit certificate to the user.
- step 1301 the local MME receives the determined CA information reported by the user;
- Step 1302 The local CBE receives the determined CA forwarded by the local MME received by the CBC.
- Step 1303 The local CBE determines whether to save the implicit certificate of the forwarded determined CA.
- Step 1304 If not saved, obtain a cross certificate of the determined CA;
- Step 1305 The local CBE sends the cross-certificate or cross-certificate information to the user.
- Step 1306 The local CBE sends the obtained cross certificate to the application server.
- Step 1307 The application server delivers cross-certificate or cross-certificate information to the user.
- An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local The CBE obtains a cross-certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or a cross-certificate or an implicit certificate of the determined CA, the local The CBE sends the obtained cross-certificate or implicit certificate to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the C-list can pass any one of the CA lists.
- the cross-certificate or the implicit certificate sent by the CA to the local CBE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 14 is a flowchart of a method for obtaining a public key according to Embodiment 4 of the present invention. Figure 14 As shown, the following steps are included:
- Step 1401 The local CA receives a global authentication authorization center CA list or a determined CA reported by the user. Information
- the core network entities in this manual use the MME in the LTE network as an example.
- the local MME receives the global CA list reported by the user, and the global CA is The list is forwarded to the local CBE, and the global CA list is forwarded by the local CBE to the local CA.
- the local MME receives the global CA list reported by the user, and the global CA is The list is forwarded to the local CBE, and the local CBE selects any CA from the global CA list, and reports any selected CA to the local CA.
- the local MME receives the global CA list reported by the user, and the local MME is from the global Select any CA in the CA list, and report any CA selected by the local MME to the local CBE, and the local CBE selects any one of the local MMEs.
- the CA report is forwarded to the local CA. Refer specifically to step 1901 and steps 1902 and 1903 of Figure 19, and steps 2001 and 2002 of Figure 20 And steps 2003.
- the local MME receives the determined CA information reported by the user, and the MME determines the determined CA. Information is forwarded to the local CBE, and the determined CA information is forwarded by the local CBE to the local CA.
- Step 1402 when the local CA is not in the CA list or the local CA is not the determined CA And obtaining, by the CA, a cross-certificate of any one of the global CA lists; or obtaining a cross-certificate of the determined CA;
- the local CA acquires the global CA list
- the local CA stores the global CA
- the cross-certificate of any CA in the list is obtained
- the cross-certificate of any one of the CAs is obtained directly from the local CA. Refer specifically to step 1504 of Figure 15.
- the local CA acquires the global CA list, and when the local CA does not store the global CA
- the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs.
- the local CA when the local CA obtains, the local CBE is arbitrarily selected from the global CA list. And when the local CA stores the cross-certificate of the arbitrarily selected one of the CAs, the cross-certificate of the arbitrarily selected one of the CAs is obtained directly from the local CA. Refer specifically to the steps in Figure 17. 1704.
- the local CA when the local CA obtains, the local CBE is arbitrarily selected from the global CA list. And when the local CA does not store the cross-certificate of the arbitrarily selected one of the CAs, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs. Refer specifically to the steps in Figure 18. 1804 and step 1805.
- the local CA when the local CA receives any CA forwarded by the local CBE, and is a local CA, the local CA obtains the cross-certificate of any CA forwarded by the local CBE.
- Step 1904 the local CA obtains the cross-certificate of any CA forwarded by the local CBE.
- the local CA when the local CA receives any CA forwarded by the local CBE, and is a local CA
- the local CA acquires a cross certificate of any CA forwarded by the local CBE. Refer specifically to the steps in Figure 20 2004 And steps 2005.
- the local CA receives the determined CA information forwarded by the local CBE, and when the local CA When the cross-certificate of the determined CA is stored, the cross-certificate of the determined CA is obtained directly from the local CA. Refer specifically to step 2104 of Figure 21.
- the local CA receives the determined CA information forwarded by the local CBE, and when the local CA If the cross-certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer specifically to step 2204 and step 2205 of Figure 22.
- Step 1403 the cross certificate obtained by the local CA, or the local CA And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA.
- a public alarm system PWS message that is sent to the user.
- the local CA sends the obtained cross certificate to the user, so that the user calculates the local CA according to the cross certificate.
- the public key and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16 Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig. Step 2206 of 22.
- the local CA sends the obtained cross-certificate information to the user, so that the user calculates the local CA according to the cross-certificate.
- the public key and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16 Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig. Step 2206 of 22.
- the method further includes:
- the CA The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate.
- the public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- steps 1506 and 1507 of Figure 15 for details. Step 1607 and step 1607 of Fig. 16, step 1706 and step 1707 of Fig. 17, step 1807 and step 1808 of Fig. 18, Fig. 19 Steps 1906 and 1907, steps 20 and 20 of Figure 20, steps 2106 and 2107 of Figure 21, steps of Figure 22 2207 and step 2208.
- step 1501 the MME receives a global CA list sent by the user;
- Step 1502 The local CBE receives the global CA forwarded by the local MME received by the CBC. List
- Step 1503 The local CA receives the global CA list forwarded by the local CBE.
- Step 1504 The local CA determines whether to save the cross-certificate of any one of the global CA lists.
- Step 1505 if yes, the information of the cross certificate or the cross certificate is delivered to the user;
- Step 1506 The local CA sends the obtained cross certificate to the application server.
- Step 1507 The application server delivers cross-certificate or cross-certificate information to the user.
- step 1601 the local MME receives a global CA list sent by the user
- Step 1602 The local CBE receives a global CA list forwarded by the local MME received by the CBC.
- Step 1603 The local CA receives the global CA list forwarded by the local CBE.
- Step 1604 the local CA determines whether the local CA has saved any CA in the global CA list.
- Step 1605 If not saved, the local CA obtains a cross-certificate of any CA in the global CA list;
- Step 1606 The local CA sends the cross-certificate or cross-certificate information to the user.
- Step 1607 The local CA sends the obtained cross certificate to the application server.
- Step 1608 The application server delivers cross-certificate or cross-certificate information to the user.
- step 1701 the local MME receives the global CA list sent by the user.
- Step 1702 The local CBE receives a global CA list forwarded by the local MME received by the CBC.
- Step 1703 The local CA receives a CA selected by the CBE from the global CA list;
- Step 1704 The local CA determines whether the local CA has saved the CA delivered by the CBE. Cross certificate
- Step 1705 If yes, the local CA sends the cross-certificate or cross-certificate information to the user;
- Step 1706 if yes, the local CA sends the obtained cross certificate to the application server;
- Step 1707 The application server delivers cross-certificate or cross-certificate information to the user.
- step 1801 the local MME receives the global CA list sent by the user.
- Step 1802 The local CBE receives a global CA list forwarded by the local MME received by the CBC.
- Step 1803 The local CA receives a CA selected by the CBE from the global CA list;
- Step 1804 The local CA determines whether the cross-certificate of the CA delivered by the CBE is saved.
- Step 1805 If not saved, the local CA obtains the cross-certificate of the CA delivered by the CBE.
- Step 1806 The local CA sends the cross-certificate or cross-certificate information to the user.
- Step 1807 The local CA sends the obtained cross certificate to the application server.
- Step 1808 The application server delivers the cross-certificate or cross-certificate information to the user.
- step 1901 the local MME receives a global CA list reported by the user.
- Step 1902 the local CBE receives the local MME received by the CBC from the global CA. Any CA selected in the list;
- Step 1903 The local CA receives the CA selected by the MME forwarded by the local CBE;
- Step 1904 The local CA determines whether the cross certificate of the CA delivered by the CBE has been saved locally.
- Step 1905 If the file is saved, the local CA sends the cross-certificate or cross-certificate information to the user.
- Step 1906 The local CA sends the obtained cross certificate to the application server.
- Step 1907 The application server delivers the cross-certificate or cross-certificate information to the user.
- step 2001 the local MME receives the global CA list sent by the user.
- Step 2002 the local CBE receives the MME arbitrarily selected from the global CA list received by the CBC. CA ;
- Step 2003 the local CA receives the CA selected by the MME forwarded by the local CBE;
- step 2004 the local CA determines whether the cross-certificate of the CA delivered by the CBE is saved.
- Step 2005 if not saved, obtain the cross-certificate of the CA delivered by the CBE;
- Step 2006 The local CA sends the cross-certificate or cross-certificate information to the user.
- Step 2007 The local CA sends the obtained cross certificate to the application server.
- Step 2008 The application server delivers the cross certificate or cross certificate information to the user.
- step 2101 the local MME receives the determined CA reported by the user
- Step 2102 The local CBE receives the determined CA forwarded by the local MME received by the CBC;
- Step 2103 The local CBE forwards the CA determined by the local CBE;
- Step 2104 The local CA determines whether to save the cross-certificate of the CA delivered by the CBE.
- Step 2105 If saved, the cross-certificate or the cross-certificate information is sent to the user;
- Step 2106 If the file is saved, the local CA sends the obtained cross certificate to the application server.
- Step 2107 The application server delivers the cross certificate or cross certificate information to the user.
- step 2201 the local MME receives the determined CA sent by the user;
- Step 2202 The local CBE receives the determined CA forwarded by the local MME.
- Step 2203 The local CBE forwards the CA determined by the local CBE;
- Step 2204 The local CA determines whether the cross-certificate of the CA delivered by the CBE is saved.
- Step 2205 If not saved, the local CA obtains the cross-certificate of the determined CA;
- Step 2206 The local CA sends the cross-certificate or cross-certificate information to the user.
- Step 2207 The local CA sends the obtained cross certificate to the application server.
- Step 2208 The application server sends the cross-certificate or cross-certificate information to the user.
- An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local The CA obtains a cross-certificate of any one of the global CA lists according to the global list or the determined CA, or a cross-certificate of the determined CA, the local CA The obtained cross-certificate is delivered to the user, so that the user can calculate the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be sent to the local through any CA in the CA list.
- the CBE's cross-certificate or implicit certificate is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 23 is a flowchart of a method for obtaining a public key according to Embodiment 5 of the present invention. as the picture shows,
- Step 2301 Determine whether the local network element stores the public key of the local CBE and/or the public key of the local CA.
- Step 2302 if yes, then the local CBE public key and / or local CA The public key is sent to the user.
- Figure 24, Figure 25, Figure 26 It is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
- the core network entities in this manual use the MME in the LTE network as an example.
- the local MME determines whether to store the local CA's public key and/or local.
- the public key of the CBE is the public key of the CBE
- Step 2402 if yes, the local MME sends the public key and/or CBE of the CA saved by the local MME. Public key.
- step 2501 the local CBE determines whether the local CBE saves the public key of the local CBE and / or the public key of the local CA;
- Step 2502 if yes, the local CBE delivers the public key and/or CBE of the CA saved by the local CBE. Public key.
- the local CA determines whether the local CA saves the local CA's public key or local.
- the public key of the CBE is the public key of the CBE
- Step 2602 If saved, the local CA sends the public key and/or CBE of the CA saved by the local CA. Public key.
- An embodiment of the present invention provides a method for obtaining a public key, where the method obtains a public key of a local CA stored by a local network element or a local
- the public key of the CBE and the public key of the obtained CA or the public key of the local CBE are sent to the user, so that the user verifies the local CBE according to the public key of the CA or the public key of the local CBE.
- FIG. 27 is a flowchart of a method for obtaining a public key according to Embodiment 6 of the present invention.
- Figure 27 As shown, the method includes the following steps:
- Step 2701 The user reports the global CA list or the determined CA information to the network element.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
- Step 2702 Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and calculating a public key of the CBE according to the cross certificate or the implicit certificate, and calculating according to the CBE
- the public key verifies the PWS message sent to the user by the local CBE.
- the user receives the cross certificate issued by the network element, or the information of the cross certificate, and calculates the local CA according to the cross certificate and the public key of one CA in the global CA corresponding to the cross certificate.
- the public key of the local CA is calculated according to the calculated public key of the local CA
- the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
- the signature of the PWS message is referred to the signature of the PWS message.
- the user receives an implicit certificate issued by the network element, or information of the implicit certificate, according to the implicit certificate and a CA of the global CA corresponding to the implicit certificate.
- Key calculation local CBE The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- the method further includes:
- the local CA public key and the local CBE are delivered according to the local CA key
- the implicit certificate in the PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- a method for obtaining a public key is provided by the embodiment of the present invention.
- the method obtains a cross certificate or an implicit certificate issued by a local network element, and calculates a public key or a local CA of the local CA according to the cross certificate or the implicit certificate.
- CBE The public key is used to verify the PWS message sent by the local CBE to the user based on the calculated public key of the local CA or the public key of the local CBE.
- FIG. 28 is a structural diagram of a device of a network element according to Embodiment 7 of the present invention.
- the network element includes the following units:
- the receiving unit 2801 is configured to receive, by the network element, a global authentication and authorization center CA list or a determined CA reported by the user.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
- CAx deploys its own network CA for the user roaming network, which is not within the planned global CA scope; CA1 belongs to the global CA scope and is one of the user-preconfigured global CAs.
- CAx If there is no mutual trust between the CAs, CAx needs to go to CA1. Establish a mutual trust relationship and obtain a cross-certificate. Otherwise, if the mutual trust relationship cannot be established, CA1 will not be able to verify the PWS message delivered by the local CBE, and cannot inform the user of PWS. Security, at this time, the user will decide whether to continue the PWS alarm message sent by the local CBE.
- the obtaining unit 2802 is configured to: when the local CA is not in the global CA list or the local CA is not the determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- the optional user can list the global CA or determine the CA.
- the information is reported to the roaming network, that is, the network element of the local network, so that the local network element determines, according to the global CA list or the determined CA information, whether the local network pre-stores any one of the global CA lists.
- Cross-certificate or implicit certificate of the CA or whether the local network pre-stores the determined CA A cross-certificate or an implicit certificate in the message. If the local network element is saved, the local network element is directly sent to the user; if the local network element is not stored, the local network element obtains a cross certificate of any one of the global lists or obtains the determined CA. Cross certificate.
- the information of the cross-certificate may be information such as the address or information of the cross-certificate, and the information of the cross-certificate enables the user to obtain the cross-certificate according to the information of the cross-certificate.
- the network element sends the obtained cross-certificate or the obtained cross-certificate information to the user
- the user corresponds to the cross-certificate and the cross-certificate corresponding to the global
- the public key of a specific CA in the CA list the public key of the local CA is calculated, and the local key is calculated according to the public key of the local CA and the implicit certificate in the PWS message sent to the user by the local CBE.
- the public key of the CBE the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE, thereby identifying the received PWS Whether the message is a legitimate public alarm message.
- the information of the implicit certificate may be information such as an address or information of an implicit certificate, and the information of the implicit certificate enables the user to obtain an implicit certificate according to the information of the implicit certificate.
- the network element sends the obtained implicit certificate or the information for obtaining the implicit certificate to the user
- the user corresponds to the global certificate corresponding to the implicit certificate and the implicit certificate.
- the public key of a specific CA in the CA list the public key of the local CBE is calculated, and the PWS message sent by the local CBE to the user is verified according to the public key of the local CBE, thereby identifying the received Whether the PWS message is a legitimate public alarm message.
- the cross-certificate or the implicit certificate obtained by the network element may be selected to send the information such as the link or address of the cross-certificate, or the link or address to which the implicit certificate is issued.
- the network element further includes a sending unit 2804, configured to:
- the network element sends the obtained cross-certificate or implicit certificate to the application server, where the cross-certificate or the implicit certificate is used by the application server, or the application server uses the cross-certificate or the implicit certificate.
- the information is sent to the user, so that the user downloads a cross certificate or an implicit certificate to the corresponding download server, and calculates the local area according to the cross certificate or the implicit certificate.
- the public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- the application server sends the information of the cross-certificate or the implicit certificate to the user, where the information includes, but is not limited to, a link or address of the information of the cross-certificate or the implicit certificate.
- the network element further includes a second sending unit 2805:
- the network element When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- An embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA by using a user. And obtaining, by the local network element, a cross certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or determining the CA
- the cross-certificate or the implicit certificate the network element sends the obtained cross-certificate or the implicit certificate to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, by A cross-certificate or an implicit certificate that is sent to the local NE by any CA in the CA list, and the public key of the local network element CBE is calculated, so as to verify the PWS sent to the user by the local CBE.
- the purpose of the message is a message.
- FIG. 29 is a structural diagram of a device of a network element according to Embodiment 8 of the present invention.
- the network element includes the following units:
- the first receiving unit 2901 is configured to receive, by the local core network entity, a global authentication and authorization center CA reported by the user. List or determined CA information;
- the local core network entity receives the global CA list reported by the user, referring to step 301 and FIG. 4 of FIG. Steps 401.
- the local core network entity receives the determined CA information reported by the user, referring to step 501 and FIG. 6 of FIG. Steps 601.
- the first obtaining unit 2902 is configured to: when the local CA is not in the global CA list or is not a determined CA And obtaining, by the local core network entity, a cross certificate of any one of the global CA lists or a cross certificate of the determined CA;
- the local core network entity receives a global CA list reported by the user, when the local CA is not in the global CA.
- the list is in the list, and when the cross-certificate of any one of the global CA lists is stored in the local core network entity, the any one of the local core network entities stored is directly obtained from the local core network entity.
- CA's cross-certificate Refer to step 302 of Figure 3.
- any CA is selected from the global CA list, and the local core network entity obtains the cross-certificate of the selected one of the CAs.
- the local core network entity receives the determined CA information reported by the user, when the local MME stores the determined When the CA cross-certifies, the cross-certificate of the determined CA stored by the local core network entity is obtained directly from the local core network entity. Refer to step 502 of Figure 5.
- the local core network entity does not store the cross-certificate of the determined CA
- the determined CA is obtained. Obtaining the cross-certificate of the determined CA. Refer to step 602 and step 603 of Figure 6.
- Third delivery unit 2903 And sending, to the user, the cross-certificate to be obtained by the local core network entity, or the information about the cross-certificate obtained by the local core network entity, so that the user calculates the local CA according to the cross-certificate The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA.
- the local MME sends the obtained cross-certificate to the user.
- Step 404 step 503 of FIG. 5, step 604 of FIG. 6;
- the local core network entity sends the obtained information of the cross-certificate to the user.
- the local core network entity sends the obtained information of the cross-certificate to the user.
- Step 404 of Figure 4 step 503 of Figure 5, and step 604 of Figure 6.
- the network element further includes a first sending unit 2904, where the first sending unit is used to:
- the core network entity sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the information of the cross-certificate to the user, so that the user obtains the cross-certificate and according to the Cross certificate calculation for the local
- the public key of the CA and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- the embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA, a local MME by using a user.
- the obtained cross-certificate is delivered to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
- the cross-certificate sent to the local NE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 30 is a structural diagram of a network element provided by Embodiment 9 of the present invention, as shown in FIG. As shown, the network element includes the following units:
- the second receiving unit 3001, the local CBE receives the global authentication and authorization center CA delivered by the local core network entity.
- the local CBE receives a global CA list forwarded by the local core network entity, and the core network entity will be global
- the CA list is forwarded directly to the local CBE.
- the core network entities in this manual use the MME in the LTE network as an example.
- the MME selects any CA from the global CA list, and selects any one of the selected CAs. Issued to the local CBE. Refer specifically to steps 1001 and 1002 of Figure 10 and steps 1101 and 1102 of Figure 11.
- the local CBE receives the determined CA information forwarded by the local MME.
- Steps 1201 and steps and steps 1301 and 1302 of Figure 13 are the steps 1201 and steps 1201 and 1302 of Figure 13.
- a second obtaining unit 3002 when the local CA is not in the CA list or the local CA is not the determined CA And obtaining, by the local CBE, a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- the implicit certificate of any CA in the list is obtained directly from the local CBE. Refer to step 803 of Figure 8 for details.
- the local CBE when the local CBE obtains the global CA list, and when the local CBE does not store the global When an implicit certificate of any one of the CAs in the CA list is selected, the local CBE selects any CA from the global CA list and obtains any CA selected. Cross certificate. Refer specifically to steps 903 and 904 of Figure 9.
- the local CBE obtains any one of the CAs selected by the MME from the global CA list
- the local CBE stores an implicit certificate of any one of the CAs selected by the MME
- the implicit certificate of the any one of the CAs is directly obtained from the local CBE.
- the local CBE obtains any one of the CAs selected by the MME from the global CA list
- the local CBE does not store the implicit certificate of any one of the CAs selected by the MME
- the cross-certificate of the any one of the CAs is obtained in the local CBE.
- the implicit certificate of the determined CA is obtained directly from the local CBE. Refer specifically to step 1203 of Figure 12.
- the local CBE receives the determined CA information forwarded by the local MME, and when the local CBE When the implicit certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer to step 1303 and step 1304 of Figure 13 for details.
- a second sending unit 3003 configured to use the cross certificate or implicit certificate that the local CBE will acquire, or the CBE And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate.
- the public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
- the local CBE sends the obtained cross-certificate or the implicit certificate to the user.
- step 804 of FIG. Step 905 of Fig. 9 step 1004 of Fig. 10, step 1105 of Fig. 11, step 1204 of Fig. 12, and step 1305 of Fig. 13.
- the local CBE sends the obtained cross-certificate information or the implicit certificate to the user.
- step 905 of FIG. 9 step 1004 of FIG. 10, step 1105 of FIG. 11, step 1204 of FIG. 12, and step 1305 of FIG. .
- the CBE can obtain any CA selected by the CBC from the global CA list.
- the specific method is similar.
- the network element further includes a second sending unit 3004:
- the CBE Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user.
- Causing a user to calculate the local based on the cross-certificate The public key of the CA, or causing the user to calculate the public key of the local CBE according to the implicit certificate, and causing the user to verify the local CBE according to the public key of the local CA or the public key of the local CBE
- the user's public alarm system PWS message is delivered. Referring specifically to step 805 and step 806 of FIG. 8, step 906 and step 907 of FIG. 9, step 1005 of FIG. And step 1006, step 1106 and step 1107 of FIG. 11, step 1205 and step 1206 of FIG. 12, step 1306 and step of FIG. 1307.
- An embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA, a local CBE.
- the obtained cross-certificate or implicit certificate is sent to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
- a cross-certificate or an implicit certificate is sent to the local CBE to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 31 is a structural diagram of a network element provided by Embodiment 10 of the present invention, as shown in FIG. As shown, the network element includes the following units:
- the third receiving unit 3101 the local CA receives the list of global certification authority CAs reported by the user or determines CA information;
- the core network entities in this manual use the MME in the LTE network as an example.
- the local MME receives the global CA list reported by the user, and the global CA is The list is forwarded to the local CBE, and the global CA list is forwarded by the local CBE to the local CA.
- the local MME receives the global CA list reported by the user, and the global CA is The list is forwarded to the local CBE, and the local CBE selects any CA from the global CA list, and reports any selected CA to the local CA.
- the local MME receives the global CA list reported by the user, and the local MME is from the global Select any CA in the CA list, and report any CA selected by the local MME to the local CBE, and the local CBE selects any one of the local MMEs.
- the CA report is forwarded to the local CA. Refer specifically to step 1901 and steps 1902 and 1903 of Figure 19, and steps 2001 and 2002 of Figure 20 And steps 2003.
- the local MME receives the determined CA information reported by the user, and the MME determines the determined CA. Information is forwarded to the local CBE, and the determined CA information is forwarded by the local CBE to the local CA.
- a third obtaining unit 3102 when the local CA is not in the CA list or the local CA is not the determined CA And obtaining, by the CA, a cross-certificate of any one of the global CA lists; or obtaining a cross-certificate of the determined CA;
- the local CA acquires the global CA list
- the local CA stores the global CA
- the cross-certificate of any CA in the list is obtained
- the cross-certificate of any one of the CAs is obtained directly from the local CA. Refer specifically to step 1504 of Figure 15.
- the local CA acquires the global CA list, and when the local CA does not store the global CA
- the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs.
- the local CA when the local CA obtains, the local CBE is arbitrarily selected from the global CA list. And when the local CA stores the cross-certificate of the arbitrarily selected one of the CAs, the cross-certificate of the arbitrarily selected one of the CAs is obtained directly from the local CA. Refer specifically to the steps in Figure 17. 1704.
- the local CA when the local CA obtains, the local CBE is arbitrarily selected from the global CA list. And when the local CA does not store the cross-certificate of the arbitrarily selected one of the CAs, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs. Refer specifically to the steps in Figure 18. 1804 and step 1805.
- the local CA when the local CA receives any CA forwarded by the local CBE, and is a local CA, the local CA obtains the cross-certificate of any CA forwarded by the local CBE.
- Step 1904 the local CA obtains the cross-certificate of any CA forwarded by the local CBE.
- the local CA when the local CA receives any CA forwarded by the local CBE, and is a local CA
- the local CA acquires a cross certificate of any CA forwarded by the local CBE. Refer specifically to the steps in Figure 20 2004 And steps 2005.
- the local CA receives the determined CA information forwarded by the local CBE, and when the local CA When the cross-certificate of the determined CA is stored, the cross-certificate of the determined CA is obtained directly from the local CA. Refer specifically to step 2104 of Figure 21.
- the local CA receives the determined CA information forwarded by the local CBE, and when the local CA If the cross-certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer specifically to step 2204 and step 2205 of Figure 22.
- a seventh sending unit 3103 the cross certificate obtained by the local CA, or the local CA And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA.
- a public alarm system PWS message that is sent to the user.
- the local CA sends the obtained cross certificate to the user, so that the user calculates the local CA according to the cross certificate.
- the public key and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16 Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig. Step 2206 of 22.
- the local CA sends the obtained cross-certificate information to the user, so that the user calculates the local CA according to the cross-certificate.
- the public key and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16 Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig. Step 2206 of 22.
- the network element further includes a third sending unit 3104:
- the CA The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate.
- the public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- steps 1506 and 1507 of Figure 15 for details. Step 1607 and step 1607 of Fig. 16, step 1706 and step 1707 of Fig. 17, step 1807 and step 1808 of Fig. 18, Fig. 19 Steps 1906 and 1907, steps 20 and 20 of Figure 20, steps 2106 and 2107 of Figure 21, steps of Figure 22 2207 and step 2208.
- An embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA, a local CA.
- the obtained cross-certificate is delivered to the user, so that the user can calculate the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be sent to the local through any CA in the CA list.
- the CBE's cross-certificate or implicit certificate is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
- FIG. 32 is a structural diagram of a device of a network element according to Embodiment 11 of the present invention.
- Figure 31 As shown, the network element includes the following units:
- the fourth sending unit 3201 is configured to determine whether the local network element stores the public key of the local CBE and/or the local CA. The public key; if so, the public key of the local CBE and/or the public key of the local CA are delivered to the user.
- Figure 24, Figure 25, Figure 26 It is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
- the core network entities in this manual use the MME in the LTE network as an example.
- the sixth delivery unit 3202 is used by the local CBE to determine whether the local CBE is saved locally.
- the eighth sending unit 3203 is used by the local CA to determine whether the local CA saves the local CA.
- the embodiment of the present invention provides a network element, where the network element obtains a public key of a local CA or a local CBE stored by a local network element.
- Public key and the public key of the obtained CA or the public key of the local CBE is sent to the user, so that the user verifies the local CBE according to the public key of the CA or the public key of the local CBE.
- FIG. 33 is a structural diagram of a device of a terminal device according to Embodiment 12 of the present invention.
- the terminal device includes the following units:
- the information reporting unit 3301 is configured to report the global CA list or the determined CA information to the network element.
- the network element includes:
- the core network node in the LTE network the network element entity is an MME, and in the UMTS network, the network element entity is SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
- Receive verification unit 3302 for Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and calculating a public key of the CBE according to the cross certificate or the implicit certificate, and calculating according to the CBE
- the public key verifies the PWS message sent to the user by the local CBE.
- the first receiving verification unit 3303 is passed The user receives the cross-certificate issued by the network element, or the information of the cross-certificate, and calculates the local CA according to the cross-certificate and the public key of one CA in the global CA corresponding to the cross-certificate
- the public key of the local CA is calculated according to the calculated public key of the local CA
- the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
- the signature of the PWS message is passed.
- the second receiving verification unit 3304 And the user receives the implicit certificate sent by the network element, or the information of the implicit certificate, and calculates the locality according to the implicit certificate and a public key of a CA in the global CA corresponding to the implicit certificate.
- CBE The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- the terminal device further includes a third receiving verification unit 3305, configured to:
- the local CA public key and the local CBE are delivered according to the local CA key
- the implicit certificate in the PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- a terminal device provided by the embodiment of the present invention, the terminal device obtains a cross certificate or an implicit certificate issued by a local network element, and calculates a public key or a local CBE of the local CA according to the cross certificate or the implicit certificate.
- the public key is used to verify the PWS message sent by the local CBE to the user based on the calculated public key of the local CA or the public key of the local CBE.
- FIG. 34 is a structural diagram of a device of a network element according to Embodiment 13 of the present invention.
- the network element 3400 is provided in the embodiment of the present invention. The specific implementation of the network device is not limited.
- the device 3400 includes:
- Processor 3401 communication interface 3402, memory 3403 through bus 3404 Complete communication with each other.
- a communication interface 3402 configured to communicate with other network elements
- the processor 3401 is configured to execute the program A.
- program A may include program code, the program code including computer operating instructions.
- the processor 3401 may be a central processing unit CPU or a specific integrated circuit ASIC ( Application Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
- ASIC Application Specific Integrated Circuit
- the memory 3403 is used to store the program A.
- Memory 3303 may contain high speed RAM
- the memory may also include a non-volatile memory.
- Program A can specifically include:
- the receiving unit 2801 is configured to receive, by the network element, a global authentication and authorization center CA list or determined CA information reported by the user;
- the obtaining unit 2802 is configured to: when the local CA is not in the global CA list or the local CA is not the determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- the cross-certificate or the implicit certificate to be obtained by the network element, or the information of the cross-certificate or the implicit certificate obtained by the network element is sent to the user, so that the user according to the cross-certificate or the implicit certificate Calculate the local CA
- the public key or the public key of the local cell broadcast entity CBE and enable the user to verify the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
- a second sending unit 2805 configured to: when the network element stores a public key of a local CBE or a local CA If the public key is used, the network element directly sends the public key of the local CBE or the public key of the local CA to the user, so that the user verifies the local CBE according to the public key of the local CBE or the public key of the local CA. PWS message sent to the user;
- Or program A can specifically include:
- the first receiving unit 2901 is configured to receive, by the local core network entity, a list of global authentication authority CAs reported by the user or determine CA information;
- the first obtaining unit 2902 is configured to: when the local CA is not in the global CA list or is not a determined CA And obtaining, by the local core network entity, a cross certificate of any one of the global CA lists or a cross certificate of the determined CA;
- Third delivery unit 2903 And sending, to the user, the cross-certificate to be obtained by the local core network entity, or the information about the cross-certificate obtained by the local core network entity, so that the user calculates the local CA according to the cross-certificate a public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA;
- First sending unit 2904 And the core network entity sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the cross-certificate information to the user, so that the user obtains the cross-certificate and Calculating the local according to the cross certificate
- the public key of the CA and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA;
- Or program A can specifically include:
- the second receiving unit 3001, the local CBE receives the global authentication and authorization center CA delivered by the local core network entity.
- a second obtaining unit 3002 when the local CA is not in the CA list or the local CA is not the determined CA And obtaining, by the local CBE, a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
- a fifth sending unit 3003 configured to use the cross certificate or implicit certificate that the local CBE will obtain, or the CBE And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate.
- the public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE;
- a second sending unit 3004 the CBE Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user.
- Or program A can specifically include:
- the third receiving unit 3101, the local CA receives the global authentication authorization center CA list or the determined CA reported by the user. Information
- a third obtaining unit 3102 when the local CA is not in the CA list or the local CA is not the determined CA And obtaining, by the CA, a cross-certificate of any one of the global CA lists; or obtaining a cross-certificate of the determined CA;
- a seventh sending unit 3103 the cross certificate obtained by the local CA, or the local CA And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA.
- a third sending unit 3104 the CA
- the obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate.
- Public key and enable the user to verify the public alarm system PWS message delivered by the local CBE according to the public key of the local CA;
- Or program A specifically includes:
- the fourth sending unit 3201 is configured to determine whether the local network element stores the public key of the local CBE and/or the local CA. The public key; if so, the public key of the local CBE and/or the public key of the local CA are delivered to the user.
- Or program A specifically includes:
- the sixth sending unit 3202 is used by the local CBE to determine whether the local CBE saves the public key of the local CBE and / Or the public key of the local CA; if so, the local CBE delivers the public key of the CA saved by the local CBE and/or the public key of the CBE.
- Or program A specifically includes:
- the eighth sending unit 3203 is configured to determine, by the local CA, whether the local CA saves the public key of the local CA or the local CBE.
- the public key if saved, the local CA issues the public key of the CA saved by the local CA and/or the public key of the CBE.
- FIG. 35 is a structural diagram of a device of a terminal device according to Embodiment 14 of the present invention.
- the terminal device 3500 is provided in the embodiment of the present invention.
- the specific implementation of the network device does not limit the specific implementation of the network device.
- the device 3500 includes:
- Processor 3501 communication interface (Communications) Interface) 3502, memory (3503), bus 3504.
- a communication interface 3502 configured to communicate with other network elements
- a processor 3501 for executing program A is a processor 3501 for executing program A.
- program A may include program code, the program code including computer operating instructions.
- the processor 3501 may be a central processing unit CPU or a specific integrated circuit ASIC ( Application Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
- ASIC Application Specific Integrated Circuit
- the memory 3503 is used to store the program A.
- Memory 3503 may contain high speed RAM
- the memory may also include a non-volatile memory.
- Program A can specifically include:
- the information reporting unit 3301 is configured to report the global CA list or the determined CA information to the network element.
- Receive verification unit 3302 for Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and calculating a public key of the CBE according to the cross certificate or the implicit certificate, and calculating according to the CBE
- the public key verifies the PWS message sent to the user by the local CBE.
- the third receiving verification unit 3305 is configured to receive, by the user, the local CBE public key and/or the local CA delivered by the network element.
- the public key authenticates the PWS message delivered by the local CBE according to the local CBE public key and/or the local CA public key.
- each unit in the program A refers to the corresponding unit in the embodiment shown in FIG. 33, and details are not described herein.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Storage Device Security (AREA)
Abstract
Disclosed is a method for obtaining a public key. The method comprises: a local CA obtaining a cross certificate of a non-local CA or a local CBE obtaining the cross certificate or an implicit certificate of the non-local CA; the local CA delivering the obtained cross certificate of the non-local CA to a user or the local CBE delivering the obtained cross certificate or implicit certificate of the non-local CA to the user, enabling the user to calculate the public key of the local CA according to the public key of the non-local CA and the cross certificate or implicit certificate of the non-local CA. This solves a problem that a PWS message cannot be verified if an implicit certificate mode is used but a UE is not configured with a global CA public key.
Description
本发明属于通信领域,尤其涉及一种获取公钥的方法及设备。 The invention belongs to the field of communications, and in particular relates to a method and a device for acquiring a public key.
公共报警系统( Public Warning System , PWS
)是一种对有可能对人类的生命和财产造成损失的自然灾害或人为事故进行警报的公共报警系统。当自然灾害,如洪水、飓风,或人为事故,如化学气体泄漏、爆炸威胁、核威胁的情况下,作为对现有广播通信系统的一种补充。
PWS 服务由电信运营商提供给用户(其内容可以由报警信息供应部门 warning notification provider
提供)。当某些事件发生时,运营商或报警信息供应部门产生报警消息 warning notification
给运营商。运营商使用他们的网络发送警报给用户。由于发布 PWS 这类消息将可能引发大规模的恐慌,所以对安全的要求也较高。根据 PWS
的安全要求,安全机制应该阻止虚假的告警通知;应该保护告警通知的完整性;应该鉴别告警通知的发送源。 Public Warning System (PWS)
) is a public alarm system that alerts natural disasters or man-made accidents that may cause damage to human life and property. When natural disasters, such as floods, hurricanes, or man-made accidents, such as chemical gas leaks, explosion threats, and nuclear threats, complement the existing broadcast communication system.
The PWS service is provided to the user by the telecommunications carrier (the content of which can be provided by the alert information provider)
Provided). When certain events occur, the operator or the alarm information supply department generates an alarm message.
To the operator. Operators use their network to send alerts to users. Since the release of such messages as PWS will likely cause large-scale panic, the security requirements are also high. According to PWS
Security requirements, security mechanisms should prevent false alarm notifications; the integrity of alarm notifications should be protected; the source of alarm notifications should be identified.
PWS 公共报警安全在 3GPP 标准组织的 SA3 组成为研究热点,不同设备商提出不同的安全解决方案。
SA3 标准在第 67 次会议讨论了基于证书的方案设想,在第 68 次会议中讨论了具体方案,并且该方案经讨论通过称为 TR33.869 中 PWS
安全备选方案之一。这个隐式证书 Implicit certificate 具体的方法是:在全球范围内规划部署几个或多个全球认证授权中心(
Certification Authority , CA ) 为 PWS 的安全初始节点。在用户( User Equipment , UE
)中预先配置了这些全球 CA 的公钥。小区广播实体周期性的从一个全球 CA 获取 Implicit certificate ,并且将 Implicit
certificate 作为 PWS 消息的安全部分进行传输。小区广播实体的公钥由 CA 的公钥和 Implicit certificate
计算得到。从而使得 UE 通过小区广播实体的公钥验证 PWS 消息的签名。方法如下: PWS public alarm security is a research hotspot in the SA3 organization of the 3GPP standards organization, and different equipment vendors propose different security solutions.
The SA3 standard discussed the certificate-based programming scenario at the 67th meeting, and the specific programme was discussed at the 68th meeting, and the programme was discussed through a PWS called TR33.869.
One of the security options. This implicit certificate Implicit certificate is specifically planned to deploy several or more global certification authority centers on a global scale (
Certification Authority, CA) is the security initial node of PWS. User ( User Equipment , UE
The public keys of these global CAs are pre-configured in ). The cell broadcast entity periodically obtains an Implicit certificate from a global CA and will Implicit
Certificate is transmitted as a secure part of the PWS message. The public key of the cell broadcast entity is the public key of the CA and Implicit certificate
Calculated. Thereby the UE verifies the signature of the PWS message by the public key of the cell broadcast entity. Methods as below:
Step1 :在全球部署多个全球 CA ,并在 UE 中配置这些 CA 的公钥; Step1: Deploy multiple global CAs globally and configure the public keys of these CAs in the UE;
Step2 :小区广播实体( Cell Broadcast Entity , CBE
)周期性的从一个全球 CA 获 Implicit Certificate ,即 CA 为 CBE 颁发 Implicit Certificate 。 Step2: Cell Broadcast Entity (CBE)
) Periodically obtain an Implicit Certificate from a global CA, that is, the CA issues an Implicit Certificate for the CBE.
Step3 :公共报警事件发生, CBE 通过小区广播中心( Cell Broadcast Centre
, CBC )向报警地点广播 PWS 消息。 PWS 消息中包含 PWS 消息以及安全部分。安全部分具体包含了 CBE 对 PWS 消息的签名以及 CA
颁发给 CBE 的 Implicit Certificate 。 Step3: Public alarm event occurs, CBE passes the cell broadcast center (Cell Broadcast Centre
, CBC) Broadcasts a PWS message to the alarm location. The PWS message contains the PWS message and the security part. The security section specifically includes the CBE's signature of the PWS message and the CA.
Implicit Certificate issued to CBE.
当 UE 接收到 PWS 消息后,首先使用本地保存的 CA 的公钥结合 PWS 消息中的
Implicit certificate 计算 CBE 的公钥( Signer's Public key ),然后通过 CBE 的公钥验证 PWS
消息的签名,从而识别接收的 PWS 消息是否是合法的公共报警消息。 When the UE receives the PWS message, it first uses the public key of the locally saved CA in combination with the PWS message.
Implicit certificate computes the CBE's public key (Signer's Public key ) and then validates the PWS via the CBE's public key
The signature of the message to identify whether the received PWS message is a legitimate public alert message.
这种基于 Implicit Certificate 的方案的基础是 UE 上部署了全球 CA
的公钥,因此当 UE 接收到含有 PWS 消息和安全的消息的消息,会使用预配置的 CA 公钥和 Implicit Certificate 证书计算 CBE
公钥进而验证 PWS 消息的签名。但是存在一种场景暴露了这种方案的问题:当 UE 漫游到这样的网络中,在该网络中没有部署全球化的 CA
,或者说出于某种原因,某个国家某运营商网络使用自己部署的 CAx ,该 CAx 不在全球 CA 列表范围。则 UE 不会预先配置到该 CAx 的信息( CAx
公钥),这样会导致 UE 在漫游到本地接收到 PWS 消息后无法验证 PWS 消息的问题。 The basis for this Implicit Certificate-based approach is the deployment of a global CA on the UE.
Public key, so when the UE receives a message containing a PWS message and a secure message, it calculates the CBE using the pre-configured CA public key and the Implicit Certificate certificate.
The public key in turn verifies the signature of the PWS message. But there is a scenario that exposes the problem of this scenario: when a UE roams into such a network, no global CA is deployed in the network.
Or, for some reason, a carrier network in a country uses its own deployed CAx, which is not in the global CA list. The UE will not pre-configure information to the CAx (CAx)
Public key) This will cause the UE to fail to verify PWS messages after roaming to receive PWS messages locally.
本发明实施例的目的在于提供 一种获取公钥的方法,所述方法解决如何使得 UE 如果没有配置在本地的
CAx 公钥,如何实现 UE 在这种场景下对 PWS 消息的验证。 An object of the embodiments of the present invention is to provide a method for obtaining a public key, which solves how to make a UE if it is not configured locally.
The CAx public key, how to implement the UE to verify the PWS message in this scenario.
第一方面, 一种获取公钥的方法,所述方法包括: In a first aspect, a method for obtaining a public key, the method comprising:
网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息; The network element receives the global authentication authority CA list or the determined CA information reported by the user;
当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球
CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; Obtaining the global when the local CA is not in the global CA list or the local CA is not the determined CA
a cross-certificate or an implicit certificate of any CA in the CA list; or a cross-certificate or an implicit certificate of the determined CA;
所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA
的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS
消息。
The network element sends the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user calculates the office according to the cross-certificate or the implicit certificate. Local CA
The public key or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system PWS delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE.
Message.
结合第一方面,在第一方面的第一种可能的实现方式中, 所述方法还包括: With reference to the first aspect, in a first possible implementation manner of the first aspect, the method further includes:
所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。
The network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server. User, causing the user to calculate the local according to the cross certificate or implicit certificate
The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
结合第一方面或者第一方面的第一种可能的实现方式,在第一方面的第二种可能的实现方式中,所述方法还包括:
In conjunction with the first aspect or the first possible implementation of the first aspect, in a second possible implementation of the first aspect, the method further includes:
当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE
的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。 When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE
The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
结合第一方面或者第一方面的第一种可能的实现方式或者第一方面的第二种可能的实现方式,在第一方面的第三种可能的实现方式中, 所述网元包括:
With reference to the first aspect, or the first possible implementation of the first aspect, or the second possible implementation of the first aspect, in a third possible implementation manner of the first aspect, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSG 或 SGSN 。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, the network element entity in the GSM or GPRS network is MSG or SGSN.
第二方面, 一种获取公钥的方法,所述方法包括: A second aspect is a method for obtaining a public key, the method comprising:
用户将全球 CA 列表或者确定的 CA 信息上报给所述网元; The user reports the global CA list or the determined CA information to the network element.
所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS
消息进行验证。
The user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and sends the PWS to the user according to the cross certificate or the implicit certificate to the local CBE.
The message is verified.
结合第二方面,在第二方面的第一种可能的实现方式中,
所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS
消息进行验证具体为: In conjunction with the second aspect, in a first possible implementation of the second aspect,
The user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and sends the PWS to the user according to the cross certificate or the implicit certificate to the local CBE.
The message is verified as follows:
所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA
的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述
PWS 消息的签名。
Receiving, by the user, a cross certificate issued by the network element, or the information of the cross certificate, calculating a local CA according to the cross certificate and a public key of a CA in the global CA corresponding to the cross certificate
The public key of the local CA is calculated according to the calculated public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
The signature of the PWS message.
结合第二方面的第一种可能的实现方式,在第二方面的第二种可能的实现方式中,
所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS
消息进行验证具体为: In conjunction with the first possible implementation of the second aspect, in a second possible implementation of the second aspect,
The user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and sends the PWS to the user according to the cross certificate or the implicit certificate to the local CBE.
The message is verified as follows:
所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE
的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。
Receiving, by the user, an implicit certificate issued by the network element, or the information of the implicit certificate, calculating a local CBE according to the implicit certificate and a public key of a CA in the global CA corresponding to the implicit certificate
The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
结合第二方面,在第二方面的第三种可能的实现方式中, 所述方法还包括: With reference to the second aspect, in a third possible implementation manner of the second aspect, the method further includes:
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE
公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。 Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE
The PWS message delivered by the local CBE is verified by the public key and / or the local CA public key.
结合第二方面的第四种可能的实现方式,在第二方面的第五种可能的实现方式中,
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE 公钥或者本地 CA 公钥对本地 CBE 下发的 PWS
消息进行验证具体为: In conjunction with the fourth possible implementation of the second aspect, in a fifth possible implementation manner of the second aspect,
Receiving, by the user, the local CBE public key and/or the local CA public key delivered by the network element, and the PWS delivered by the local CBE according to the local CBE public key or the local CA public key
The message is verified as follows:
当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE
下发的 PWS 消息; When the user receives the local CBE public key delivered by the network element, the local CBE is directly verified according to the local CBE public key.
PWS message delivered;
或者当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE
下发的 PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。 Or when the user receives the local CA public key delivered by the network element, according to the local CA public key and the local CBE
The implicit certificate in the issued PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
第三方面, 一种网元,所述网元包括: A third aspect, a network element, where the network element includes:
接收单元,用于接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息; a receiving unit, configured to receive a global certification authority CA list or determined CA information reported by the user;
获取单元,用于当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA
时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; An obtaining unit, configured to: when the local CA is not in the global CA list or the local CA is not the determined CA
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
第一下发单元,用于所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统
PWS 消息。
a first sending unit, configured to send, by the network element, a cross-certificate or an implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local
The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE.
PWS message.
结合第三方面,在第三方面的第一种可能的实现方式中,
所述网元还包括上发单元,所述上发单元包括: In conjunction with the third aspect, in a first possible implementation of the third aspect,
The network element further includes a sending unit, where the sending unit includes:
所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。
The network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server. User, causing the user to calculate the local according to the cross certificate or implicit certificate
The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
结合第三方面或者第三方面的第一种可能的实现方式,在第三方面的第二种可能的实现方式中,
所述网元还包括第二下发单元,所述第二下单元包括: With reference to the third aspect or the first possible implementation manner of the third aspect, in a second possible implementation manner of the third aspect,
The network element further includes a second sending unit, where the second lower unit includes:
当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE
的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。 When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE
The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
结合第三方面的第二种可能的实现方式,在第三方面的第三种可能的实现方式中, 所述网元包括: In conjunction with the second possible implementation of the third aspect, in a third possible implementation manner of the third aspect, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSG 或 SGSN 。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, the network element entity in the GSM or GPRS network is MSG or SGSN.
第四方面, 一种终端设备,所述终端设备包括: A fourth aspect, a terminal device, where the terminal device includes:
信息上发单元,用于用户将全球 CA 列表或者确定的 CA 信息上报给所述网元; An information sending unit, configured to report, by the user, the global CA list or the determined CA information to the network element;
接收验证单元,用于所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的
PWS 消息进行验证。
Receiving a verification unit, configured to receive, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and send the local CBE to the local CBE according to the cross certificate or the implicit certificate users
The PWS message is verified.
结合第四方面,在第四方面的第一种可能的实现方式中,
所述接收验证单元包括第一接收验证单元,所述第一接收验证单元包括: With reference to the fourth aspect, in a first possible implementation manner of the fourth aspect,
The receiving and verifying unit includes a first receiving and verifying unit, and the first receiving and verifying unit includes:
所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA
的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述
PWS 消息的签名。
Receiving, by the user, a cross certificate issued by the network element, or the information of the cross certificate, calculating a local CA according to the cross certificate and a public key of a CA in the global CA corresponding to the cross certificate
The public key of the local CA is calculated according to the calculated public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
The signature of the PWS message.
结合第四方面的第一种可能的实现方式,在第四方面的第二种可能的实现方式中,
所述接收验证单元包括第二接收验证单元,所述第二接收验证单元包括: With reference to the first possible implementation manner of the fourth aspect, in a second possible implementation manner of the fourth aspect,
The receiving verification unit includes a second receiving verification unit, and the second receiving verification unit includes:
所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE
的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。
Receiving, by the user, an implicit certificate issued by the network element, or the information of the implicit certificate, calculating a local CBE according to the implicit certificate and a public key of a CA in the global CA corresponding to the implicit certificate
The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
结合第四方面的第二种可能的实现方式,在第四方面的第三种可能的实现方式中,
所述终端设备还包括第三接收验证单元,所述第三接收验证单元包括: In conjunction with the second possible implementation of the fourth aspect, in a third possible implementation manner of the fourth aspect,
The terminal device further includes a third receiving verification unit, where the third receiving verification unit includes:
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE
公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。 Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE
The PWS message delivered by the local CBE is verified by the public key and / or the local CA public key.
结合第四方面的第四种可能的实现方式,在第四方面的第五种可能的实现方式中,
所述第三接收验证单元包括: In conjunction with the fourth possible implementation of the fourth aspect, in a fifth possible implementation manner of the fourth aspect,
The third receiving verification unit includes:
当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE
下发的 PWS 消息; When the user receives the local CBE public key delivered by the network element, the local CBE is directly verified according to the local CBE public key.
PWS message delivered;
或者当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE
下发的 PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。 Or when the user receives the local CA public key delivered by the network element, according to the local CA public key and the local CBE
The implicit certificate in the issued PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
第五方面, 一种网元,所述网元包括: A fifth aspect, a network element, where the network element includes:
接收单元,用于接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息; a receiving unit, configured to receive a global certification authority CA list or determined CA information reported by the user;
获取单元,用于当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA
时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; An obtaining unit, configured to: when the local CA is not in the global CA list or the local CA is not the determined CA
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
第一下发单元,用于所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统
PWS 消息。
a first sending unit, configured to send, by the network element, a cross-certificate or an implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local
The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE.
PWS message.
结合第五方面,在第五方面的第一种可能的实现方式中,
所述网元包括处理器,通信接口,存储器和总线; With reference to the fifth aspect, in a first possible implementation manner of the fifth aspect,
The network element includes a processor, a communication interface, a memory, and a bus;
其中处理器、通信接口、存储器通过总线完成相互间的通信; The processor, the communication interface, and the memory complete communication with each other through the bus;
所述通信接口,用于与其他王宇设备进行通信; The communication interface is configured to communicate with other Wangyu devices;
所述处理器,用于执行程序; The processor is configured to execute a program;
所述存储器,用于存放程序; The memory is configured to store a program;
其中程序用于 接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息;当本地 CA
不在所述全球 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA
的交叉证书或隐式证书;所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统
PWS 消息。 The program is used to receive the global certification authority CA list or the determined CA information reported by the user; when the local CA
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists when the global CA list or the local CA is not the determined CA; or obtaining the determined CA
a cross-certificate or an implicit certificate; the network element will send the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local
The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE.
PWS message.
结合第五方面的第一种可能的实现方式,在第五方面的第二种可能的实现方式中,
所述网元还包括上发单元,所述上发单元包括: With reference to the first possible implementation manner of the fifth aspect, in a second possible implementation manner of the fifth aspect,
The network element further includes a sending unit, where the sending unit includes:
所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。
The network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server. User, causing the user to calculate the local according to the cross certificate or implicit certificate
The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
结合第五方面的第一种可能的实现方式或者第五方面的第二种可能的实现方式,在第五方面的第三种可能的实现方式中, 所述网元
还包括第二下发单元,所述第二下单元包括:
With reference to the first possible implementation manner of the fifth aspect, or the second possible implementation manner of the fifth aspect, in a third possible implementation manner of the fifth aspect, the network element
Also included is a second delivery unit, the second lower unit comprising:
当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE
的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。 When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE
The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
结合第五方面的第三种可能的实现方式,在第五方面的第四种可能的实现方式中, 所述网元包括: With reference to the third possible implementation manner of the fifth aspect, in a fourth possible implementation manner of the fifth aspect, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSG 或 SGSN 。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, the network element entity in the GSM or GPRS network is MSG or SGSN.
第六方面, 一种终端设备,所述终端设备包括: A sixth aspect, a terminal device, where the terminal device includes:
信息上发单元,用于用户将全球 CA 列表或者确定的 CA 信息上报给所述网元; An information sending unit, configured to report, by the user, the global CA list or the determined CA information to the network element;
接收验证单元,用于所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的
PWS 消息进行验证。
Receiving a verification unit, configured to receive, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and send the local CBE to the local CBE according to the cross certificate or the implicit certificate users
The PWS message is verified.
结合第六方面,在第六方面的第一种可能的实现方式中,
所述网元包括处理器,通信接口,存储器和总线; With reference to the sixth aspect, in a first possible implementation manner of the sixth aspect,
The network element includes a processor, a communication interface, a memory, and a bus;
其中处理器、通信接口、存储器通过总线完成相互间的通信; The processor, the communication interface, and the memory complete communication with each other through the bus;
所述通信接口,用于与其他网元进行通信; The communication interface is configured to communicate with other network elements;
所述处理器,用于执行程序; The processor is configured to execute a program;
所述存储器,用于存放程序; The memory is configured to store a program;
其中程序用于 用户将全球 CA 列表或者确定的 CA
信息上报给所述网元;所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的
PWS 消息进行验证。 The program is used by the user to list the global CA or determine the CA.
The information is reported to the network element; the user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and the local CBE is performed according to the cross certificate or the implicit certificate. Sent to the user
The PWS message is verified.
结合第六方面的第一种可能的实现方式,在第六方面的第二种可能的实现方式中中,
所述接收验证单元包括第一接收验证单元,所述第一接收验证单元包括: With reference to the first possible implementation manner of the sixth aspect, in a second possible implementation manner of the sixth aspect,
The receiving and verifying unit includes a first receiving and verifying unit, and the first receiving and verifying unit includes:
所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA
的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述
PWS 消息的签名。
Receiving, by the user, a cross certificate issued by the network element, or the information of the cross certificate, calculating a local CA according to the cross certificate and a public key of a CA in the global CA corresponding to the cross certificate
The public key of the local CA is calculated according to the calculated public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
The signature of the PWS message.
结合第六方面的第二种可能的实现方式,在第六方面的第三种可能的实现方式中,
所述接收验证单元包括第二接收验证单元,所述第二接收验证单元包括: In conjunction with the second possible implementation of the sixth aspect, in a third possible implementation manner of the sixth aspect,
The receiving verification unit includes a second receiving verification unit, and the second receiving verification unit includes:
所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE
的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。
Receiving, by the user, an implicit certificate issued by the network element, or the information of the implicit certificate, calculating a local CBE according to the implicit certificate and a public key of a CA in the global CA corresponding to the implicit certificate
The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
结合第六方面的第三种可能的实现方式,在第六方面的第四种可能的实现方式中,
所述终端设备还包括第三接收验证单元,所述第三接收验证单元包括: In conjunction with the third possible implementation of the sixth aspect, in a fourth possible implementation manner of the sixth aspect,
The terminal device further includes a third receiving verification unit, where the third receiving verification unit includes:
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE
公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。 Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE
The PWS message delivered by the local CBE is verified by the public key and / or the local CA public key.
结合第六方面的第四种可能的实现方式,在第六方面的第五种可能的实现方式中,
所述第三接收验证单元包括: With reference to the fourth possible implementation manner of the sixth aspect, in a fifth possible implementation manner of the sixth aspect,
The third receiving verification unit includes:
当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE
下发的 PWS 消息; When the user receives the local CBE public key delivered by the network element, the local CBE is directly verified according to the local CBE public key.
PWS message delivered;
或者当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE
下发的 PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。 Or when the user receives the local CA public key delivered by the network element, according to the local CA public key and the local CBE
The implicit certificate in the issued PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
本发明实施例提供一种获取公钥的方法,所述方法通过用户上报全球 CA 列表或者确定的 CA ,本地
MME 根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书,或者确定的 CA 的交叉证书,所述本地 MME
将获取的交叉证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个 CA
下发给本地网元的交叉证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local
Obtaining, by the MME, a cross-certificate of any one of the global CA lists, or a cross-certificate of the determined CA, according to the global list or the determined CA, the local MME
The obtained cross-certificate is delivered to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
The cross-certificate sent to the local NE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings to be used in the embodiments will be briefly described below. It is obvious that the drawings in the following description are only some embodiments of the present invention. Those skilled in the art can also obtain other drawings based on these drawings without paying for creative labor.
图 1 是本发明实施例一提供的一种获取公钥的方法流程图; 1 is a flowchart of a method for obtaining a public key according to Embodiment 1 of the present invention;
图 2 是本发明实施例二提供的一种获取公钥的方法流程图; 2 is a flowchart of a method for obtaining a public key according to Embodiment 2 of the present invention;
图 3 是本发明实施例二提供的一种获取公钥的方法示意图; 3 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention;
图 4 是本发明实施例二提供的一种获取公钥的方法示意图; 4 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention;
图 5 是本发明实施例二提供的一种获取公钥的方法示意图; FIG. 5 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention; FIG.
图 6 是本发明实施例二提供的一种获取公钥的方法示意图; 6 is a schematic diagram of a method for obtaining a public key according to Embodiment 2 of the present invention;
图 7 是本发明实施例三提供的一种获取公钥的方法流程图; 7 is a flowchart of a method for obtaining a public key according to Embodiment 3 of the present invention;
图 8 是本发明实施例三提供的一种获取公钥的方法示意图; FIG. 8 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention; FIG.
图 9 是本发明实施例三提供的一种获取公钥的方法示意图; FIG. 9 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention; FIG.
图 10 是本发明实施例三提供的一种获取公钥的方法示意图; FIG. 10 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention; FIG.
图 11 是本发明实施例三提供的一种获取公钥的方法示意图; FIG. 11 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention; FIG.
图 12 是本发明实施例三提供的一种获取公钥的方法示意图; FIG. 12 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention; FIG.
图 13 是本发明实施例三提供的一种获取公钥的方法示意图; FIG. 13 is a schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention; FIG.
图 14 是本发明实施例四提供的一种获取公钥的方法流程图; 14 is a flowchart of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 15 是本发明实施例四提供的一种获取公钥的方法示意图; 15 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 16 是本发明实施例四提供的一种获取公钥的方法示意图; 16 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 17 是本发明实施例四提供的一种获取公钥的方法示意图; 17 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 18 是本发明实施例四提供的一种获取公钥的方法示意图; 18 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 19 是本发明实施例四提供的一种获取公钥的方法示意图; FIG. 19 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention; FIG.
图 20 是本发明实施例四提供的一种获取公钥的方法示意图; 20 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 21 是本发明实施例四提供的一种获取公钥的方法示意图; 21 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention;
图 22 是本发明实施例四提供的一种获取公钥的方法示意图; FIG. 22 is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention; FIG.
图 23 是本发明实施例五提供的一种获取公钥的方法流程图; 23 is a flowchart of a method for obtaining a public key according to Embodiment 5 of the present invention;
图 24 是本发明实施例五提供的一种获取公钥的方法示意图; 24 is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention;
图 25 是本发明实施例五提供的一种获取公钥的方法示意图; 25 is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention;
图 26 是本发明实施例五提供的一种获取公钥的方法示意图; 26 is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention;
图 27 是本发明实施例六提供的一种获取公钥的方法示意图; 27 is a schematic diagram of a method for obtaining a public key according to Embodiment 6 of the present invention;
图 28 是本发明实施例七提供的一种网元的装置结构图; 28 is a structural diagram of a device of a network element according to Embodiment 7 of the present invention;
图 29 是本发明实施例八提供的一种网元的装置结构图; 29 is a structural diagram of a device of a network element according to Embodiment 8 of the present invention;
图 30 是本发明实施例九提供的一种网元的装置结构图; 30 is a structural diagram of a device of a network element according to Embodiment 9 of the present invention;
图 31 是本发明实施例十提供的一种网元的装置结构图; 31 is a structural diagram of a device of a network element according to Embodiment 10 of the present invention;
图 32 是本发明实施例十一提供的一种网元的装置结构图; 32 is a structural diagram of a device of a network element according to Embodiment 11 of the present invention;
图 33 是本发明实施例十二提供的一种终端设备的装置结构图; 33 is a structural diagram of a device of a terminal device according to Embodiment 12 of the present invention;
图 34 是本发明实施例十三提供的一种网元的装置结构图; FIG. 34 is a structural diagram of a device of a network element according to Embodiment 13 of the present invention; FIG.
图 35 是本发明实施例十四提供的一种终端设备的装置结构图。 35 is a structural diagram of a device of a terminal device according to Embodiment 14 of the present invention.
为了使本发明的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本发明进行进一步详细说明。应当理解,此处所描述的具体实施例仅仅用以解释本发明,并不用于限定本发明。
The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It is understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
以上所述仅为本发明的较佳实施例而已,并不用以限制本发明,凡在本发明的精神和原则之内所作的任何修改、等同替换和改进等,均应包含在本发明的保护范围之内。
The above is only the preferred embodiment of the present invention, and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection of the present invention. Within the scope.
实施例一 Embodiment 1
参考图 1 ,图 1 是本发明实施例一提供的一种获取公钥的方法流程图。如图 1 所示: Referring to FIG. 1, FIG. 1 is a flowchart of a method for obtaining a public key according to Embodiment 1 of the present invention. As shown in Figure 1:
步骤 101 ,网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息; Step 101: The network element receives the global authentication and authorization center CA list or the determined CA information reported by the user.
本步骤中,所述网元包括: In this step, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSC 或 SGSN ,或者是 CBC 节点。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
当用户附着到漫游网络,并且可选的用户没有预先存储所述漫游网络的本地 CA 或本地 CBE
的公钥时,无法对本地 CBE 下发的 PWS 消息或者其他消息进行验证。如果全球 CA 之间建立互信关系,则说明用户对 PWS 消息的认证可以通过 CA
之间的信任实现。因此,如果 UE 漫游到一种部署了 CAX 的特殊网络,为了实现 PWS 消息的认证,可以通过
CAX 与 CA1 之间建立安全关联并使得 CAX 获得 CA1 的交叉证书。交叉证书是 CA
之间互相签发的一种证书。其中, CAx 为用户漫游的网络部署自己网络的 CA ,不属于规划的全球 CA 范围内; CA1 属于全球 CA
范围,是用户预配置的全球 CA 之一。When a user attaches to a roaming network, and the optional user does not pre-store the public key of the local CA or the local CBE of the roaming network, the PWS message or other message delivered by the local CBE cannot be verified. If a mutual trust relationship is established between global CAs, the user's authentication of PWS messages can be achieved through trust between CAs. Therefore, if the UE roams to a special network where CA X is deployed, in order to authenticate the PWS message, a security association can be established between CA X and CA1 and CA X can obtain the cross-certificate of CA1. A cross-certificate is a certificate issued between CAs. Among them, CAx deploys its own network CA for the user roaming network, which is not within the planned global CA scope; CA1 belongs to the global CA scope and is one of the user-preconfigured global CAs.
如果 CA 之间没有建立互信关系,则 CAx 需要向 CA1
建立互信关系,获取交叉证书。否则,如果无法建立互信关系, CA1 会将无法验证本地 CBE 下发的 PWS 消息,无法告知用户 PWS
的安全性,此时将由用户决定是否继续信息本地 CBE 下发的 PWS 报警消息。 If there is no mutual trust between the CAs, CAx needs to go to CA1.
Establish a mutual trust relationship and obtain a cross-certificate. Otherwise, if the mutual trust relationship cannot be established, CA1 will not be able to verify the PWS message delivered by the local CBE, and cannot inform the user of PWS.
Security, at this time, the user will decide whether to continue the PWS alarm message sent by the local CBE.
步骤 102 ,当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA
时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; Step 102: When the local CA is not in the global CA list or the local CA is not the determined CA
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
本步骤中,所述可选的用户可以将全球 CA 列表或者确定的 CA
信息上报给所述漫游网络,即本地网络的网元,使得本地网元根据所述全球 CA 列表或者确定的 CA 信息判断本地网络是否预先存储所述全球 CA 列表中任意一个
CA 的交叉证书或者隐式证书,或者本地网络是否预先存储所述确定的 CA
信息中的交叉证书或者隐式证书。若本地网元已存,则直接下发给用户;若本地网元未存,则本地网元获取所述全球列表中任意一个 CA 的交叉证书或者获取所述确定的 CA
的交叉证书。 In this step, the optional user can list the global CA or determine the CA.
The information is reported to the roaming network, that is, the network element of the local network, so that the local network element determines, according to the global CA list or the determined CA information, whether the local network pre-stores any one of the global CA lists.
Cross-certificate or implicit certificate of the CA, or whether the local network pre-stores the determined CA
A cross-certificate or an implicit certificate in the message. If the local network element is saved, the local network element is directly sent to the user; if the local network element is not stored, the local network element obtains a cross certificate of any one of the global lists or obtains the determined CA.
Cross certificate.
步骤 103
,所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA
的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。 Step 103
The network element sends the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate or the implicit certificate obtained by the network element to the user, so that the user calculates the office according to the cross-certificate or the implicit certificate. Local CA
The public key or the public key of the local cell broadcast entity CBE, and enable the user to verify the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
本步骤中,所述交叉证书的信息可以是交叉证书的地址或信息等信息,所述交叉证书的信息使得用户根据所述交叉证书的信息获取交叉证书。当所述网元将获取的交叉证书或者获得交叉证书信息下发给用户时,用户根据交叉证书和交叉证书对应的全球
CA 列表中的某一个特定 CA 的公钥,计算出本地 CA 的公钥,根据本地 CA 的公钥和本地 CBE 下发给用户的 PWS 消息中的隐式证书计算出本地
CBE 的公钥,所述用户根据所述本地 CBE 的公钥对本地 CBE 下发给用户的 PWS 消息进行验证,从而识别接收的 PWS
消息是否是合法的公共报警信息。
In this step, the information of the cross-certificate may be information such as the address or information of the cross-certificate, and the information of the cross-certificate enables the user to obtain the cross-certificate according to the information of the cross-certificate. When the network element sends the obtained cross-certificate or the obtained cross-certificate information to the user, the user corresponds to the cross-certificate and the cross-certificate corresponding to the global
The public key of a specific CA in the CA list, the public key of the local CA is calculated, and the local key is calculated according to the public key of the local CA and the implicit certificate in the PWS message sent to the user by the local CBE.
The public key of the CBE, the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE, thereby identifying the received PWS
Whether the message is a legitimate public alarm message.
本步骤中,所述隐式证书的信息可以是隐式证书的地址或信息等信息,所述隐式证书的信息使得用户根据所述隐式证书的信息获取隐式证书。所述网元将获取的隐式证书或者获取隐式证书的信息下发给用户时,用户根据所述隐式证书和隐式证书对应的全球
CA 列表中的某一个特定 CA 的公钥,计算出本地 CBE 的公钥,根据本地 CBE 的公钥对本地 CBE 下发给用户的 PWS 消息进行验证,从而识别接收的
PWS 消息是否是合法的公共报警信息。
In this step, the information of the implicit certificate may be information such as an address or information of an implicit certificate, and the information of the implicit certificate enables the user to obtain an implicit certificate according to the information of the implicit certificate. When the network element sends the obtained implicit certificate or the information for obtaining the implicit certificate to the user, the user corresponds to the global certificate corresponding to the implicit certificate and the implicit certificate.
The public key of a specific CA in the CA list, the public key of the local CBE is calculated, and the PWS message sent by the local CBE to the user is verified according to the public key of the local CBE, thereby identifying the received
Whether the PWS message is a legitimate public alarm message.
为了减少宽带,在所述网元获取的交叉证书或隐式证书时,可以选择下发所述交叉证书的链接或者地址等信息,或者选择下发所述隐式证书的链接或者地址等信息。
In order to reduce the bandwidth, the cross-certificate or the implicit certificate obtained by the network element may be selected to send the information such as the link or address of the cross-certificate, or the link or address to which the implicit certificate is issued.
进一步,所述方法还包括: Further, the method further includes:
所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述应用服务器将所述交叉证书的或隐式证书的信息下发给用户,使得用户到对应的下载服务器下载交叉证书或隐式证书,并根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。
The network element sends the obtained cross-certificate or implicit certificate to the application server, where the cross-certificate or the implicit certificate is used by the application server, or the application server uses the cross-certificate or the implicit certificate. The information is sent to the user, so that the user downloads a cross certificate or an implicit certificate to the corresponding download server, and calculates the local area according to the cross certificate or the implicit certificate.
The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
其中,所述应用服务器将所述交叉证书的或隐式证书的信息下发给用户,所述信息包括但不限于交叉证书的或隐式证书的信息的链接或地址。
The application server sends the information of the cross-certificate or the implicit certificate to the user, where the information includes, but is not limited to, a link or address of the information of the cross-certificate or the implicit certificate.
进一步,所述方法还包括: Further, the method further includes:
当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE
的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。 When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE
The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
本发明实施例提供一种获取公钥的方法,所述方法通过用户上报全球 CA 列表或者确定的 CA
,本地网元根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书或者隐式证书,或者确定的 CA
的交叉证书或者隐式证书,所述网元将获取的交叉证书或者隐式证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过
CA 列表内的任意一个 CA 下发给本地网元的交叉证书或者隐式证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS
消息的目的。 An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA by a user.
And obtaining, by the local network element, a cross certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or determining the CA
The cross-certificate or the implicit certificate, the network element sends the obtained cross-certificate or the implicit certificate to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, by
A cross-certificate or an implicit certificate that is sent to the local NE by any CA in the CA list, and the public key of the local network element CBE is calculated, so as to verify the PWS sent to the user by the local CBE.
The purpose of the message.
实施例二 Embodiment 2
参考图 2 ,图 2 是本发明实施例二提供的一种获取公钥的方法流程图。 Referring to FIG. 2, FIG. 2 is a flowchart of a method for obtaining a public key according to Embodiment 2 of the present invention.
步骤 201 ,所述本地核心网实体接收用户上报的全球认证授权中心 CA 列表或者确定的 CA
信息; Step 201: The local core network entity receives a global authentication authorization center CA list or a determined CA reported by the user.
Information
可优选的,所述本地核心网实体接收用户上报的全球 CA 列表,参考图 3 的步骤 301 和图 4
的步骤 401 。 Preferably, the local core network entity receives the global CA list reported by the user, referring to step 301 and FIG. 4 of FIG.
Steps 401.
可优选的,所述本地核心网实体接收用户上报的确定的 CA 信息,参考图 5 的步骤 501 和图 6
的步骤 601 。 Preferably, the local core network entity receives the determined CA information reported by the user, referring to step 501 and FIG. 6 of FIG.
Steps 601.
步骤 202 ,当本地 CA 不在所述全球 CA 列表中或者不是确定的 CA
时,则所述本地核心网实体获取所述全球 CA 列表中任意一个 CA 的交叉证书或者确定的 CA 的交叉证书; Step 202: When the local CA is not in the global CA list or is not a determined CA
And obtaining, by the local core network entity, a cross certificate of any one of the global CA lists or a cross certificate of the determined CA;
可优选的,所述本地核心网实体接收用户上报的全球 CA 列表,当本地 CA 不在所述全球 CA
列表中时,且当所述本地核心网实体中存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接从本地核心网实体中获取所述本地核心网实体存储的所述任意一个
CA 的交叉证书。参考图 3 的步骤 302 。 Preferably, the local core network entity receives a global CA list reported by the user, when the local CA is not in the global CA.
When the list is in the list, and when the cross-certificate of any one of the global CA lists is stored in the local core network entity, the any one of the local core network entities stored is directly obtained from the local core network entity.
CA's cross-certificate. Refer to step 302 of Figure 3.
可优选的,当所述本地核心网实体中未存储所述全球 CA 列表中任意一个 CA
的交叉证书时,则从所述全球 CA 列表中选取任意一个 CA ,所述本地核心网实体获取所述选取的任意一个 CA 的交叉证书。参考图 4 的步骤 402 和步骤
403 。 Preferably, when the local core network entity does not store any one of the global CA lists
When the cross-certificate is obtained, any CA is selected from the global CA list, and the local core network entity obtains the cross-certificate of the selected one of the CAs. Refer to step 402 and steps in Figure 4.
403.
可优选的,所述本地核心网实体接收用户上报的确定的 CA 信息,当所述本地 MME 存储所述确定的
CA 的交叉证书时,则直接从本地核心网实体中获取所述本地核心网实体存储的所述确定的 CA 的交叉证书。参考图 5 的步骤 502 。 Preferably, the local core network entity receives the determined CA information reported by the user, when the local MME stores the determined
When the CA cross-certifies, the cross-certificate of the determined CA stored by the local core network entity is obtained directly from the local core network entity. Refer to step 502 of Figure 5.
可优选的,当所述本地核心网实体没有存储所述确定的 CA 的交叉证书时,则从所述确定的 CA
中获取所述确定的 CA 的交叉证书。参考图 6 的步骤 602 和步骤 603 。 Preferably, when the local core network entity does not store the cross-certificate of the determined CA, then the determined CA is obtained.
Obtaining the cross-certificate of the determined CA. Refer to step 602 and step 603 of Figure 6.
步骤 203
,所述本地核心网实体将获取的交叉证书,或者所述本地核心网实体将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证所述本地 CBE 下发给用户的 PWS 消息。 Step 203
And the local core network entity sends the obtained cross-certificate, or the information of the cross-certificate obtained by the local core network entity to the user, so that the user calculates the local CA according to the cross-certificate
The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA.
本步骤中,所述本地 MME 将获取的交叉证书下发给用户,具体参考图 3 的步骤 303 、图 4
的步骤 404 、图 5 的步骤 503 、图 6 的步骤 604 ; In this step, the local MME sends the obtained cross-certificate to the user. For details, refer to step 303 and Figure 4 in Figure 3.
Step 404, step 503 of FIG. 5, step 604 of FIG. 6;
可优选的,所述本地核心网实体将获取的交叉证书的信息下发给用户,具体参考图 3 的步骤 303 、图
4 的步骤 404 、图 5 的步骤 503 、图 6 的步骤 604 。 Preferably, the local core network entity sends the obtained information of the cross-certificate to the user. For details, refer to step 303 and Figure 3 of Figure 3.
Step 404 of Figure 4, step 503 of Figure 5, and step 604 of Figure 6.
进一步,所述方法还包括: Further, the method further includes:
所述核心网实体将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户获得所述交叉证书并根据所述交叉证书计算所述本地
CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。 具体参考图 3 的步骤 304 和步骤 305
,图 4 的步骤 405 和步骤 406 ,图 5 的步骤 504 和步骤 505 ,图 6 的步骤 605 和步骤 606 。
The core network entity sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the information of the cross-certificate to the user, so that the user obtains the cross-certificate and according to the Cross certificate calculation for the local
The public key of the CA, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA. Refer specifically to step 304 and step 305 of Figure 3.
Step 405 and step 406 of Fig. 4, step 504 and step 505 of Fig. 5, step 605 and step 606 of Fig. 6.
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
图 3 、图 4 、图 5 、图 6
是本发明实施例二提供的一种获取公钥的方法,具体参考如下: Figure 3, Figure 4, Figure 5, Figure 6
It is a method for obtaining a public key provided by Embodiment 2 of the present invention, and the specific reference is as follows:
如图 3 所示,步骤 301 ,所述 MME 接收用户上报的全球 CA 列表; As shown in FIG. 3, in step 301, the MME receives a global CA list reported by the user;
步骤 302 ,所述 MME 检查接收的所述全球 CA 列表与本地 MME
保存的是否一致; Step 302, the MME checks the received global CA list and the local MME.
Whether the preservation is consistent;
步骤 303 ,若一致,所述 MME 下发本地保存的交叉证书或者交叉证书的信息; Step 303: If the MME is consistent, the MME sends the locally saved cross certificate or cross certificate information.
或者采用 Or adopt
步骤 304 ,若一致,所述 MME 上发本地保存的交叉证书给应用服务器; Step 304: If the MME is consistent, the MME sends the locally saved cross certificate to the application server.
步骤 305 ,所述应用服务器下发交叉证书或者交叉证书的信息给所述用户。 Step 305: The application server sends the cross-certificate or cross-certificate information to the user.
如图 4 所示,步骤 401 ,所述 MME 接收用户上报的全球 CA 列表; As shown in FIG. 4, in step 401, the MME receives a global CA list reported by the user;
步骤 402 ,所述 MME 检查接收的 CA 列表与本地 MME 保存的是否一致; Step 402: The MME checks whether the received CA list is consistent with that saved by the local MME.
步骤 403 ,若不一致,则所述 MME 获取 CA 列表中任意一个 CA 的交叉证书; Step 403: If not, the MME obtains a cross-certificate of any one of the CAs in the CA list;
步骤 404 ,所述 MME 下发交叉证书或者交叉的信息到用户; Step 404: The MME sends a cross certificate or cross information to the user.
或者采用 Or adopt
步骤 405 ,所述 MME 上发获取的交叉证书到应用服务器; Step 405: The MME sends the obtained cross certificate to the application server.
步骤 406 ,所述应用服务器将交叉证书或者交叉证书的信息下发到用户。 Step 406: The application server delivers the information of the cross certificate or the cross certificate to the user.
如图 5 所示,步骤 501 ,所述 MME 获取用户上发的确定的 CA 信息; As shown in FIG. 5, in step 501, the MME obtains the determined CA information sent by the user.
步骤 502 ,所述 MME 检查本地是否保存确定的 CA 的交叉证书; Step 502: The MME checks whether a cross certificate of the determined CA is saved locally.
步骤 503 ,若是,则所述 MME 下发本地保存的交叉证书或者交叉证书的信息; Step 503, if yes, the MME sends the locally saved cross certificate or cross certificate information;
或者采用 Or adopt
步骤 504 ,若是,则上发本地 MME 保存的交叉证书到应用服务器; Step 504, if yes, the cross certificate issued by the local MME is sent to the application server;
步骤 505 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 505: The application server delivers the cross certificate or cross certificate information to the user.
如图 6 所示,步骤 601 ,用户上发确定的 CA 信息到所述 MME ; As shown in FIG. 6, in step 601, the user sends the determined CA information to the MME;
步骤 602 ,所述 MME 检查本地是否保存确定的 CA 的交叉证书; Step 602: The MME checks whether a cross certificate of the determined CA is saved locally.
步骤 603 ,若未保存,则所述 MME 获取所述确定的 CA 的交叉证书; Step 603: If not saved, the MME obtains the cross certificate of the determined CA.
步骤 604 ,所述 MME 下发交叉证书或者交叉证书的信息到用户; Step 604: The MME sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 605 ,所述 MME 上发获取的交叉证书到应用服务器; Step 605: The MME sends the obtained cross certificate to the application server.
步骤 606 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 606: The application server sends the information of the cross certificate or the cross certificate to the user.
本发明实施例提供一种获取公钥的方法,所述方法通过用户上报全球 CA 列表或者确定的 CA ,本地
MME 根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书,或者确定的 CA 的交叉证书,所述本地 MME
将获取的交叉证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个 CA
下发给本地网元的交叉证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local
Obtaining, by the MME, a cross-certificate of any one of the global CA lists, or a cross-certificate of the determined CA, according to the global list or the determined CA, the local MME
The obtained cross-certificate is delivered to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
The cross-certificate sent to the local NE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
实施例三 Embodiment 3
参考图 7 ,图 7 是本发明实施例三提供的一种获取公钥的方法流程图。如图 7 所示: Referring to FIG. 7, FIG. 7 is a flowchart of a method for obtaining a public key according to Embodiment 3 of the present invention. As shown in Figure 7:
步骤 701 ,所述本地 CBE 接收所述本地核心网实体下发的全球认证授权中心 CA
列表或者确定的 CA 信息。 Step 701: The local CBE receives the global authentication and authorization center CA delivered by the local core network entity.
List or determined CA information.
可优选的,所述本地 CBE 接收所述本地核心网实体转发的全球 CA 列表,所述核心网实体将全球
CA 列表直接转发给本地 CBE 。具体参考图 8 的步骤 801 和步骤 802 和图 9 的步骤 901 和步骤 902 。 Preferably, the local CBE receives a global CA list forwarded by the local core network entity, and the core network entity will be global
The CA list is forwarded directly to the local CBE. Refer specifically to steps 801 and 802 of Figure 8 and steps 901 and 902 of Figure 9.
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
可优选的,所述 MME 从所述全球 CA 列表中选取任意一个 CA ,并将所述选取的任意一个 CA
下发给本地 CBE 。具体参考图 10 的步骤 1001 和步骤 1002 和图 11 的步骤 1101 和步骤 1102 。 Preferably, the MME selects any CA from the global CA list, and selects any one of the selected CAs.
Issued to the local CBE. Refer specifically to steps 1001 and 1002 of Figure 10 and steps 1101 and 1102 of Figure 11.
可优选的,所述本地 CBE 接收所述本地 MME 转发的确定的 CA 信息。具体参考图 12
的步骤 1201 和步骤和图 13 的步骤 1301 和步骤 1302 。 Preferably, the local CBE receives the determined CA information forwarded by the local MME. Refer to Figure 12 for details.
Steps 1201 and steps and steps 1301 and 1302 of Figure 13.
步骤 702 ,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA
时,则所述本地 CBE 获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; Step 702: When the local CA is not in the CA list or the local CA is not the determined CA
And obtaining, by the local CBE, a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
可优选的,当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 存储所述全球 CA
列表中任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书。具体参考图 8 的步骤 803 。 Preferably, when the local CBE obtains the global CA list, and when the local CBE stores the global CA
When an implicit certificate of any CA in the list is obtained, the implicit certificate of any one of the CAs is obtained directly from the local CBE. Refer to step 803 of Figure 8 for details.
可优选的,当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 未存储所述全球
CA 列表中任意一个 CA 的隐式证书时,则所述本地 CBE 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA
的交叉证书。具体参考图 9 的步骤 903 和步骤 904 。 Preferably, when the local CBE obtains the global CA list, and when the local CBE does not store the global
When an implicit certificate of any one of the CAs in the CA list is selected, the local CBE selects any CA from the global CA list and obtains any CA selected.
Cross certificate. Refer specifically to steps 903 and 904 of Figure 9.
可优选的,当本地 CBE 获取的是所述 MME 从所述全球 CA 列表中选取的任意一个 CA
时,并且当所述本地 CBE 存储所述 MME 选取的任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书。具体参考图 10
的步骤 1003 。 Preferably, when the local CBE obtains any one of the CAs selected by the MME from the global CA list
And when the local CBE stores an implicit certificate of any one of the CAs selected by the MME, the implicit certificate of the any one of the CAs is directly obtained from the local CBE. Refer to Figure 10 for details.
Step 1003.
可优选的,当本地 CBE 获取的是所述 MME 从所述全球 CA 列表中选取的任意一个 CA
时,并且当所述本地 CBE 未存储所述 MME 选取的任意一个 CA 的隐式证书时,则所述本地 CBE 中获取所述任意一个 CA 的交叉证书。具体参考图 11
的步骤 1103 和步骤 1104 。 Preferably, when the local CBE obtains any one of the CAs selected by the MME from the global CA list
And when the local CBE does not store the implicit certificate of any one of the CAs selected by the MME, the cross-certificate of the any one of the CAs is obtained in the local CBE. Refer to Figure 11 for details.
Steps 1103 and 1104.
可优选的,当所述本地 CBE 接收所述本地 MME 转发的确定的 CA 信息,并且当本地 CBE
存储所述确定的 CA 的隐式证书时,则直接从本地 CBE 中获取所述确定的 CA 的隐式证书。具体参考图 12 的步骤 1203 。 Preferably, when the local CBE receives the determined CA information forwarded by the local MME, and when the local CBE
When the implicit certificate of the determined CA is stored, the implicit certificate of the determined CA is obtained directly from the local CBE. Refer specifically to step 1203 of Figure 12.
可优选的,当所述本地 CBE 接收所述本地 MME 转发的确定的 CA 信息,且当本地 CBE
未存储所述确定的 CA 的隐式证书时,则获取所述确定的 CA 的交叉证书。具体参考图 13 的步骤 1303 和步骤 1304 。 Preferably, when the local CBE receives the determined CA information forwarded by the local MME, and when the local CBE
When the implicit certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer to step 1303 and step 1304 of Figure 13 for details.
步骤 703 ,所述本地 CBE 将获取的交叉证书或者隐式证书,或者所述 CBE
将获取的交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE
的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。 Step 703, the cross certificate or implicit certificate that the local CBE will acquire, or the CBE
And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate.
The public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
可优选的,所述本地 CBE 将获取的交叉证书或者隐式证书下发给用户,具体参考图 8 的步骤 804
、图 9 的步骤 905 、图 10 的步骤 1004 、图 11 的步骤 1105 、图 12 的步骤 1204 、图 13 的步骤 1305 。 Preferably, the local CBE sends the obtained cross-certificate or the implicit certificate to the user. For details, refer to step 804 of FIG.
Step 905 of Fig. 9, step 1004 of Fig. 10, step 1105 of Fig. 11, step 1204 of Fig. 12, and step 1305 of Fig. 13.
可优选的,所述本地 CBE 将获取的交叉证书的信息或者隐式证书下发给用户,具体参考图 8 的步骤
804 、图 9 的步骤 905 、图 10 的步骤 1004 、图 11 的步骤 1105 、图 12 的步骤 1204 、图 13 的步骤 1305
。 Preferably, the local CBE sends the obtained cross-certificate information or the implicit certificate to the user. For details, refer to the steps in Figure 8.
804, step 905 of FIG. 9, step 1004 of FIG. 10, step 1105 of FIG. 11, step 1204 of FIG. 12, and step 1305 of FIG.
.
实施例中, CBE 可以获得由 CBC 从所述全球 CA 列表中选取的任意一个 CA
,具体方法类似。 In an embodiment, the CBE can obtain any CA selected by the CBC from the global CA list.
The specific method is similar.
进一步,所述方法还包括: Further, the method further includes:
所述 CBE
将获取的交叉证书或者隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或者所述隐式证书,或者所述交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地
CA 的公钥,或者使得用户根据所述隐式证书计算所述本地 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE
下发用户的公共报警系统 PWS 消息。 具体参考图 8 的步骤 805 和步骤 806 ,图 9 的步骤 906 和步骤 907 ,图 10 的步骤 1005
和步骤 1006 ,图 11 的步骤 1106 和步骤 1107 ,图 12 的步骤 1205 和步骤 1206 ,图 13 的步骤 1306 和步骤
1307 。 The CBE
Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user. Causing a user to calculate the local based on the cross-certificate
The public key of the CA, or causing the user to calculate the public key of the local CBE according to the implicit certificate, and causing the user to verify the local CBE according to the public key of the local CA or the public key of the local CBE
The user's public alarm system PWS message is delivered. Referring specifically to step 805 and step 806 of FIG. 8, step 906 and step 907 of FIG. 9, step 1005 of FIG.
And step 1006, step 1106 and step 1107 of FIG. 11, step 1205 and step 1206 of FIG. 12, step 1306 and step of FIG.
1307.
图 8 、图 9 、图 10 、图 11 、图 12 、图 13
是本发明实施例三提供的一种获取公钥的方法示意图。实施例中, CBE 也可以可以获得由 CBC 从所述全球 CA 列表中选取的任意一个 CA
,具体方法类似。 Figure 8, Figure 9, Figure 10, Figure 11, Figure 12, Figure 13
A schematic diagram of a method for obtaining a public key according to Embodiment 3 of the present invention. In an embodiment, the CBE may also obtain any CA selected by the CBC from the global CA list.
The specific method is similar.
如图 8 所示,步骤 801 ,所述本地 MME 接收用户上发的全球 CA 列表; As shown in FIG. 8, in step 801, the local MME receives a global CA list sent by the user.
步骤 802 ,所述本地 CBE 接收 CBC 接收的所述本地 MME 转发的全球 CA
列表; Step 802, the local CBE receives the global CA forwarded by the local MME received by the CBC
List
步骤 803 ,所述本地 CBE 判断是否保存全球 CA 列表中任意一个 CA
的隐式证书; Step 803, the local CBE determines whether to save any CA in the global CA list.
Implicit certificate
步骤 804 ,若是,则所述本地 CBE 下发隐式证书或者隐式证书的信息到用户; Step 804, if yes, the local CBE sends the information of the implicit certificate or the implicit certificate to the user;
或者采用 Or adopt
步骤 805 ,若是,则所述本地 CBE 上发获取的隐式证书到应用服务器; Step 805, if yes, the local CBE sends the obtained implicit certificate to the application server;
步骤 806 ,所述应用服务器将隐式证书或者隐式证书的信息下发到用户。 Step 806: The application server sends the information of the implicit certificate or the implicit certificate to the user.
如图 9 所示,步骤 901 ,所述本地 MME 接收用户上发的全球 CA 列表; As shown in FIG. 9, in step 901, the local MME receives a global CA list sent by the user;
步骤 902 ,所述本地 CBE 转发 CBC 接收的所述本地 MME 转发的全球 CA
列表; Step 902: The local CBE forwards the global CA forwarded by the local MME received by the CBC.
List
步骤 903 ,所述本地 CBE 判断是否保存全球 CA 列表中任意一个 CA
的隐式证书; Step 903, the local CBE determines whether to save any CA in the global CA list.
Implicit certificate
步骤 904 ,本地 CBE 未保存全球 CA 列表中任意一个 CA 的交叉证书,则获取任意一个
CA 的交叉证书; Step 904: If the local CBE does not save the cross-certificate of any one of the global CA lists, obtain any one.
CA's cross-certificate;
步骤 905 ,若是,则下发交叉证书或者交叉证书的连接到用户; Step 905, if yes, the cross-certificate or the cross-certificate is delivered to the user;
或者采用 Or adopt
步骤 906 ,若是,则上发获取的交叉证书到应用服务器; Step 906, if yes, the obtained cross certificate is sent to the application server;
步骤 907 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 907: The application server delivers the information of the cross certificate or the cross certificate to the user.
参考图 10 ,步骤 1001 ,所述 MME 接收用户上发的全球 CA 列表; Referring to FIG. 10, step 1001, the MME receives a global CA list sent by a user;
步骤 1002 ,所述 CBE 接收 CBC 接收的所述 MME 从全球 CA
列表中任意选取的一个 CA ; Step 1002, the CBE receives the MME received by the CBC from a global CA.
Any CA selected in the list;
步骤 1003 ,本地 CBE 判断是否保存下发的任意一个 CA 的隐式证书; Step 1003: The local CBE determines whether to save the implicit certificate of any CA that is delivered;
步骤 1004 ,若是,则所述本地 CBE 下发隐式证书或者隐式证书的信息到用户; Step 1004, if yes, the local CBE sends the information of the implicit certificate or the implicit certificate to the user;
或者采用 Or adopt
步骤 1005 ,所述本地 CBE 上发获取的隐式证书到应用服务器; Step 1005: The local CBE sends the obtained implicit certificate to the application server.
步骤 1006 ,所述应用服务器下发隐式证书或者隐式证书的信息到用户。 Step 1006: The application server sends the information of the implicit certificate or the implicit certificate to the user.
如图 11 所述,步骤 1101 ,所述 MME 接收用户上发的全球 CA 列表; As shown in FIG. 11, step 1101, the MME receives a global CA list sent by the user;
步骤 1102 ,本地 CBE 接收 CBC 接收的 MME 从全球 CA 列表中任意选取的一个
CA ; Step 1102: The local CBE receives an MME randomly selected from the global CA list received by the CBC.
CA ;
步骤 1103 ,本地 CBE 判断是否保存下发的任意一个 CA 的隐式证书; Step 1103: The local CBE determines whether to save the implicit certificate of any CA that is delivered;
步骤 1104 ,若未保存,则本地 CBE 获取所述任意一个 CA 的交叉证书; Step 1104: If not saved, the local CBE obtains the cross-certificate of the any one of the CAs;
步骤 1105 ,本地 CBE 下发交叉证书或者交叉证书的信息到所述用户; Step 1105: The local CBE sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 1106 ,所述本地 CBE 上发获取的交叉证书到应用服务器; Step 1106: The local CBE sends the obtained cross certificate to the application server.
步骤 1107 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1107: The application server delivers the cross certificate or cross certificate information to the user.
参考图 12 ,步骤 1201 ,所述 MME 接收用户上发的确定的 CA 信息; Referring to FIG. 12, step 1201, the MME receives the determined CA information sent by the user.
步骤 1202 ,本地 CBE 接收所述 MME 转发的确定的 CA 信息; Step 1202: The local CBE receives the determined CA information forwarded by the MME.
步骤 1203 ,所述本地 CBE 判断是否保存转发的确定的 CA 的隐式证书; Step 1203: The local CBE determines whether to save the implicit certificate of the forwarded determined CA.
步骤 1204 ,若是,则下发隐式证书或者隐式证书的信息到用户; Step 1204, if yes, sending the information of the implicit certificate or the implicit certificate to the user;
或者采用 Or adopt
步骤 1205 ,所述本地 CBE 上发获取的隐式证书到应用服务器; Step 1205: The local CBE sends the obtained implicit certificate to the application server.
步骤 1206 ,所述应用服务器下发隐式证书或者隐式证书的信息到用户。 Step 1206: The application server sends the information of the implicit certificate or the implicit certificate to the user.
如图 13 所示,步骤 1301 ,所述本地 MME 接收用户上报的确定的 CA 信息; As shown in FIG. 13, in step 1301, the local MME receives the determined CA information reported by the user;
步骤 1302 ,本地 CBE 接收 CBC 接收的本地 MME 转发的确定的 CA
信息; Step 1302: The local CBE receives the determined CA forwarded by the local MME received by the CBC.
Information
步骤 1303 ,本地 CBE 判断是否保存转发的确定的 CA 的隐式证书; Step 1303: The local CBE determines whether to save the implicit certificate of the forwarded determined CA.
步骤 1304 ,若未保存,则获取确定的 CA 的交叉证书; Step 1304: If not saved, obtain a cross certificate of the determined CA;
步骤 1305 ,本地 CBE 下发交叉证书或者交叉证书的信息到用户; Step 1305: The local CBE sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 1306 ,本地 CBE 上发获取的交叉证书到应用服务器; Step 1306: The local CBE sends the obtained cross certificate to the application server.
步骤 1307 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1307: The application server delivers cross-certificate or cross-certificate information to the user.
本发明实施例提供一种获取公钥的方法,所述方法通过用户上报全球 CA 列表或者确定的 CA ,本地
CBE 根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书,或者确定的 CA 的交叉证书或隐式证书,所述本地
CBE 将获取的交叉证书或隐式证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个
CA 下发给本地 CBE 的交叉证书或隐式证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local
The CBE obtains a cross-certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or a cross-certificate or an implicit certificate of the determined CA, the local
The CBE sends the obtained cross-certificate or implicit certificate to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the C-list can pass any one of the CA lists.
The cross-certificate or the implicit certificate sent by the CA to the local CBE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
实施例四 Embodiment 4
参考图 14 ,图 14 是本发明实施例四提供的一种获取公钥的方法流程图。如图 14
所示,包括如下步骤: Referring to FIG. 14, FIG. 14 is a flowchart of a method for obtaining a public key according to Embodiment 4 of the present invention. Figure 14
As shown, the following steps are included:
步骤 1401 ,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA
信息; Step 1401: The local CA receives a global authentication authorization center CA list or a determined CA reported by the user.
Information
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
可优选的,所述本地 MME 接收用户上报的所述全球 CA 列表,将所述全球 CA
列表转发给所述本地 CBE ,由所述本地 CBE 将所述全球 CA 列表转发给所述本地 CA 。具体参考图 15 的步骤 1501 和步骤 1502 和步骤
1503 ,和图 16 的步骤 1601 和步骤 1602 和步骤 1603 。 Preferably, the local MME receives the global CA list reported by the user, and the global CA is
The list is forwarded to the local CBE, and the global CA list is forwarded by the local CBE to the local CA. Refer specifically to step 1501 and step 1502 and steps in Figure 15.
1503, and step 1601 and step 1602 and step 1603 of Figure 16.
可优选的,所述本地 MME 接收用户上报的所述全球 CA 列表,将所述全球 CA
列表转发给所述本地 CBE ,由所述本地 CBE 从所述全球 CA 列表中选取任意一个 CA ,并将选取的任意一个 CA 上报给所述本地 CA 。具体参考
17 的步骤 1701 和步骤 1702 和步骤 1703 ,和图 18 的步骤 1801 和步骤 1802 和步骤 1803 。 Preferably, the local MME receives the global CA list reported by the user, and the global CA is
The list is forwarded to the local CBE, and the local CBE selects any CA from the global CA list, and reports any selected CA to the local CA. Specific reference
Step 17 of step 1701 and step 1702 and step 1703, and step 1801 of step 18 and step 1802 and step 1803.
可优选的,所述本地 MME 接收用户上报的所述全球 CA 列表,由所述本地 MME 从所述全球
CA 列表中选取任意一个 CA ,并将所述本地 MME 选取的任意一个 CA 上报给本地 CBE ,由所述本地 CBE 将所述本地 MME 选取的任意一个
CA 上报转发给所述本地 CA 。具体参考图 19 的步骤 1901 和步骤 1902 和步骤 1903 ,和图 20 的步骤 2001 和步骤 2002
和步骤 2003 。 Preferably, the local MME receives the global CA list reported by the user, and the local MME is from the global
Select any CA in the CA list, and report any CA selected by the local MME to the local CBE, and the local CBE selects any one of the local MMEs.
The CA report is forwarded to the local CA. Refer specifically to step 1901 and steps 1902 and 1903 of Figure 19, and steps 2001 and 2002 of Figure 20
And steps 2003.
可优选的,所述本地 MME 接收用户上报的所述确定的 CA 信息,所述 MME 将所述确定的 CA
信息转发给所述本地 CBE ,并由所述本地 CBE 将所述确定的 CA 信息转发给所述本地 CA 。具体参考 21 的步骤 2101 和步骤 2102 和步骤
2103 ,和图 22 的步骤步骤 2201 和步骤 2202 和步骤 2203 。 Preferably, the local MME receives the determined CA information reported by the user, and the MME determines the determined CA.
Information is forwarded to the local CBE, and the determined CA information is forwarded by the local CBE to the local CA. Refer to step 2101 and step 2102 and steps in step 21 for details.
2103, and step 22, step 2201 and step 2202 and step 2203 of FIG.
步骤 1402 ,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA
时,则所述 CA 获取所述全球 CA 列表中任意一个 CA 的交叉证书;或者获取所述确定的 CA 的交叉证书; Step 1402, when the local CA is not in the CA list or the local CA is not the determined CA
And obtaining, by the CA, a cross-certificate of any one of the global CA lists; or obtaining a cross-certificate of the determined CA;
可优选的,当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 存储所述全球 CA
列表中任意一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意一个 CA 的交叉证书。具体参考图 15 的步骤 1504 。 Preferably, when the local CA acquires the global CA list, and when the local CA stores the global CA
When the cross-certificate of any CA in the list is obtained, the cross-certificate of any one of the CAs is obtained directly from the local CA. Refer specifically to step 1504 of Figure 15.
可优选的,当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 未存储所述全球 CA
列表中任意一个 CA 的交叉证书时,则所述本地 CA 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书。具体参考图
16 的步骤 1604 和步骤 1605 。 Preferably, when the local CA acquires the global CA list, and when the local CA does not store the global CA
When the cross-certificate of any one of the CAs in the list is selected, the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs. Specific reference map
Step 16 of step 16 and step 1605.
可优选的,当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA
时,并当本地 CA 存储所述任意选取的一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意选取的一个 CA 的交叉证书。具体参考图 17 的步骤
1704 。 Preferably, when the local CA obtains, the local CBE is arbitrarily selected from the global CA list.
And when the local CA stores the cross-certificate of the arbitrarily selected one of the CAs, the cross-certificate of the arbitrarily selected one of the CAs is obtained directly from the local CA. Refer specifically to the steps in Figure 17.
1704.
可优选的,当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA
时,并当本地 CA 未存储所述任意选取的一个 CA 的交叉证书时,则所述本地 CA 获取所述任意选取的一个 CA 的交叉证书。具体参考图 18 的步骤
1804 和步骤 1805 。 Preferably, when the local CA obtains, the local CBE is arbitrarily selected from the global CA list.
And when the local CA does not store the cross-certificate of the arbitrarily selected one of the CAs, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs. Refer specifically to the steps in Figure 18.
1804 and step 1805.
可优选的当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA
存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 直接从本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。具体参考图 19
的步骤 1904 。 Preferably, when the local CA receives any CA forwarded by the local CBE, and is a local CA
When the CA is forwarded by the local CBE, the local CA obtains the cross-certificate of any CA forwarded by the local CBE. Refer to Figure 19 for details.
Step 1904.
可优选的当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA
未存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。具体参考图 20 的步骤 2004
和步骤 2005 。 Preferably, when the local CA receives any CA forwarded by the local CBE, and is a local CA
When any CA of the local CBE forwarding is not stored, the local CA acquires a cross certificate of any CA forwarded by the local CBE. Refer specifically to the steps in Figure 20 2004
And steps 2005.
可优选的,当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA
存储所述确定的 CA 的交叉证书时,则直接从本地 CA 中获取所述确定的 CA 的交叉证书。具体参考图 21 的步骤 2104 。 Preferably, when the local CA receives the determined CA information forwarded by the local CBE, and when the local CA
When the cross-certificate of the determined CA is stored, the cross-certificate of the determined CA is obtained directly from the local CA. Refer specifically to step 2104 of Figure 21.
可优选的,当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA
未存储所述确定的 CA 的交叉证书,则获取所述确定的 CA 的交叉证书。具体参考图 22 的步骤 2204 和步骤 2205 。 Preferably, when the local CA receives the determined CA information forwarded by the local CBE, and when the local CA
If the cross-certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer specifically to step 2204 and step 2205 of Figure 22.
步骤 1403 ,所述本地 CA 将获取的交叉证书,或者所述本地 CA
将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE
下发给用户的公共报警系统 PWS 消息。 Step 1403, the cross certificate obtained by the local CA, or the local CA
And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA.
A public alarm system PWS message that is sent to the user.
可优选的,所述本地 CA 将获取的交叉证书下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。具体参考图 15 的步骤 1505 ,图 16 的步骤 1606
,图 17 的步骤 1705 ,图 18 的步骤 1806 ,图 19 的步骤 1905 ,图 20 的步骤 2006 ,图 21 的步骤 2105 ,图
22 的步骤 2206 。 Preferably, the local CA sends the obtained cross certificate to the user, so that the user calculates the local CA according to the cross certificate.
The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16
Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig.
Step 2206 of 22.
可优选的,所述本地 CA 将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。具体参考图 15 的步骤 1505 ,图 16 的步骤 1606
,图 17 的步骤 1705 ,图 18 的步骤 1806 ,图 19 的步骤 1905 ,图 20 的步骤 2006 ,图 21 的步骤 2105 ,图
22 的步骤 2206 。 Preferably, the local CA sends the obtained cross-certificate information to the user, so that the user calculates the local CA according to the cross-certificate.
The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16
Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig.
Step 2206 of 22.
进一步,所述方法还包括: Further, the method further includes:
所述 CA
将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。 具体参考图 15 的步骤 1506 和步骤 1507
,图 16 的步骤 1607 和步骤 1607 ,图 17 的步骤 1706 和步骤 1707 ,图 18 的步骤 1807 和步骤 1808 ,图 19
的步骤 1906 和步骤 1907 ,图 20 的步骤 2007 和步骤 2008 ,图 21 的步骤 2106 和步骤 2107 ,图 22 的步骤
2207 和步骤 2208 。 The CA
The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate.
The public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA. Refer to steps 1506 and 1507 of Figure 15 for details.
Step 1607 and step 1607 of Fig. 16, step 1706 and step 1707 of Fig. 17, step 1807 and step 1808 of Fig. 18, Fig. 19
Steps 1906 and 1907, steps 20 and 20 of Figure 20, steps 2106 and 2107 of Figure 21, steps of Figure 22
2207 and step 2208.
图 15 、图 16 、图 17 、图 18 、图 19 、图 20 、图 21 、图 22
是本发明实施例四提供的一种获取公钥的方法示意图。具体如下: Figure 15, Figure 16, Figure 17, Figure 18, Figure 19, Figure 20, Figure 21, Figure 22
It is a schematic diagram of a method for obtaining a public key according to Embodiment 4 of the present invention. details as follows:
如图 15 所示,步骤 1501 ,所述 MME 接收用户上发的全球 CA 列表; As shown in FIG. 15, in step 1501, the MME receives a global CA list sent by the user;
步骤 1502 ,本地 CBE 接收 CBC 接收的所述本地 MME 转发的全球 CA
列表; Step 1502: The local CBE receives the global CA forwarded by the local MME received by the CBC.
List
步骤 1503 ,本地 CA 接收所述本地 CBE 转发的全球 CA 列表; Step 1503: The local CA receives the global CA list forwarded by the local CBE.
步骤 1504 ,本地 CA 判断是否保存全球 CA 列表中任意一个 CA 的交叉证书; Step 1504: The local CA determines whether to save the cross-certificate of any one of the global CA lists.
步骤 1505 ,若是,则下发交叉证书或者交叉证书的信息到用户; Step 1505, if yes, the information of the cross certificate or the cross certificate is delivered to the user;
或者采用 Or adopt
步骤 1506 ,本地 CA 上发获取的交叉证书到应用服务器; Step 1506: The local CA sends the obtained cross certificate to the application server.
步骤 1507 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1507: The application server delivers cross-certificate or cross-certificate information to the user.
参考图 16 ,步骤 1601 ,所述本地 MME 接收用户上发的全球 CA 列表; Referring to FIG. 16, step 1601, the local MME receives a global CA list sent by the user;
步骤 1602 ,本地 CBE 接收 CBC 接收的本地 MME 转发的全球 CA 列表; Step 1602: The local CBE receives a global CA list forwarded by the local MME received by the CBC.
步骤 1603 ,本地 CA 接收本地 CBE 转发的全球 CA 列表; Step 1603: The local CA receives the global CA list forwarded by the local CBE.
步骤 1604 ,本地 CA 判断本地是否已保存全球 CA 列表中任意一个 CA
的交叉证书; Step 1604, the local CA determines whether the local CA has saved any CA in the global CA list.
Cross certificate
步骤 1605 ,若未保存,本地 CA 获取全球 CA 列表中任意一个 CA 的交叉证书; Step 1605: If not saved, the local CA obtains a cross-certificate of any CA in the global CA list;
步骤 1606 ,所述本地 CA 下发交叉证书或者交叉证书的信息到用户; Step 1606: The local CA sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 1607 ,所述本地 CA 上发获取的交叉证书到应用服务器; Step 1607: The local CA sends the obtained cross certificate to the application server.
步骤 1608 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1608: The application server delivers cross-certificate or cross-certificate information to the user.
如图 17 所示,步骤 1701 ,本地 MME 接收用户上发的全球 CA 列表; As shown in FIG. 17, in step 1701, the local MME receives the global CA list sent by the user.
步骤 1702 ,本地 CBE 接收 CBC 接收的本地 MME 转发的全球 CA 列表; Step 1702: The local CBE receives a global CA list forwarded by the local MME received by the CBC.
步骤 1703 ,本地 CA 接收 CBE 从全球 CA 列表中任意选取的一个 CA ; Step 1703: The local CA receives a CA selected by the CBE from the global CA list;
步骤 1704 ,本地 CA 判断本地 CA 是否已保存 CBE 下发的 CA
的交叉证书; Step 1704: The local CA determines whether the local CA has saved the CA delivered by the CBE.
Cross certificate
步骤 1705 ,若是,本地 CA 下发交叉证书或者交叉证书的信息到用户; Step 1705: If yes, the local CA sends the cross-certificate or cross-certificate information to the user;
或者采用 Or adopt
步骤 1706 ,若是,本地 CA 上发获取的交叉证书到应用服务器; Step 1706, if yes, the local CA sends the obtained cross certificate to the application server;
步骤 1707 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1707: The application server delivers cross-certificate or cross-certificate information to the user.
如图 18 所示,步骤 1801 ,本地 MME 接收用户上发的全球 CA 列表; As shown in FIG. 18, in step 1801, the local MME receives the global CA list sent by the user.
步骤 1802 ,本地 CBE 接收 CBC 接收的本地 MME 转的全球 CA 列表; Step 1802: The local CBE receives a global CA list forwarded by the local MME received by the CBC.
步骤 1803 ,本地 CA 接收 CBE 从全球 CA 列表中任意选取的一个 CA ; Step 1803: The local CA receives a CA selected by the CBE from the global CA list;
步骤 1804 ,本地 CA 判断是否已保存 CBE 下发的 CA 的交叉证书; Step 1804: The local CA determines whether the cross-certificate of the CA delivered by the CBE is saved.
步骤 1805 ,若未保存,则本地 CA 获取 CBE 下发的 CA 的交叉证书; Step 1805: If not saved, the local CA obtains the cross-certificate of the CA delivered by the CBE.
步骤 1806 ,本地 CA 下发交叉证书或者交叉证书的信息到用户; Step 1806: The local CA sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 1807 ,本地 CA 上发获取的交叉证书到应用服务器; Step 1807: The local CA sends the obtained cross certificate to the application server.
步骤 1808 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1808: The application server delivers the cross-certificate or cross-certificate information to the user.
如图 19 所示,步骤 1901 ,所述本地 MME 接收用户上报的全球 CA 列表; As shown in FIG. 19, in step 1901, the local MME receives a global CA list reported by the user.
步骤 1902 ,本地 CBE 接收 CBC 接收的本地 MME 从全球 CA
列表中任意选取的一个 CA; Step 1902, the local CBE receives the local MME received by the CBC from the global CA.
Any CA selected in the list;
步骤 1903 ,本地 CA 接收本地 CBE 转发的 MME 选择的 CA ; Step 1903: The local CA receives the CA selected by the MME forwarded by the local CBE;
步骤 1904 ,本地 CA 判断本地是否已经保存 CBE 下发的 CA 的交叉证书; Step 1904: The local CA determines whether the cross certificate of the CA delivered by the CBE has been saved locally.
步骤 1905 ,若保存,则本地 CA 下发交叉证书或者交叉证书的信息到用户; Step 1905: If the file is saved, the local CA sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 1906 ,本地 CA 上发获取的交叉证书到应用服务器; Step 1906: The local CA sends the obtained cross certificate to the application server.
步骤 1907 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 1907: The application server delivers the cross-certificate or cross-certificate information to the user.
如图 20 所示,步骤 2001 ,本地 MME 接收用户上发的全球 CA 列表; As shown in FIG. 20, in step 2001, the local MME receives the global CA list sent by the user.
步骤 2002 ,本地 CBE 接收 CBC 接收的 MME 从全球 CA 列表中任意选取的一个
CA ; Step 2002, the local CBE receives the MME arbitrarily selected from the global CA list received by the CBC.
CA ;
步骤 2003 ,本地 CA 接收本地 CBE 转发的 MME 选择的 CA ; Step 2003, the local CA receives the CA selected by the MME forwarded by the local CBE;
步骤 2004 ,本地 CA 判断是否已保存 CBE 下发的 CA 的交叉证书; In step 2004, the local CA determines whether the cross-certificate of the CA delivered by the CBE is saved.
步骤 2005 ,若未保存,则获取 CBE 下发的 CA 的交叉证书; Step 2005, if not saved, obtain the cross-certificate of the CA delivered by the CBE;
步骤 2006 ,本地 CA 下发交叉证书或者交叉证书的信息到用户; Step 2006: The local CA sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 2007 ,本地 CA 上发获取的交叉证书到应用服务器; Step 2007: The local CA sends the obtained cross certificate to the application server.
步骤 2008 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 2008: The application server delivers the cross certificate or cross certificate information to the user.
如图 21 所示,步骤 2101 ,本地 MME 接收用户上报的确定的 CA ; As shown in FIG. 21, in step 2101, the local MME receives the determined CA reported by the user;
步骤 2102 ,本地 CBE 接收 CBC 接收的本地 MME 转发的确定的 CA ; Step 2102: The local CBE receives the determined CA forwarded by the local MME received by the CBC;
步骤 2103 ,本地 CBE 转发本地 CBE 确定的 CA ; Step 2103: The local CBE forwards the CA determined by the local CBE;
步骤 2104 ,本地 CA 判断是否保存 CBE 下发的 CA 的交叉证书; Step 2104: The local CA determines whether to save the cross-certificate of the CA delivered by the CBE.
步骤 2105 ,若保存,则下发交叉证书或者交叉证书的信息到用户; Step 2105: If saved, the cross-certificate or the cross-certificate information is sent to the user;
或者采用 Or adopt
步骤 2106 ,若保存,则本地 CA 上发获取的交叉证书到应用服务器; Step 2106: If the file is saved, the local CA sends the obtained cross certificate to the application server.
步骤 2107 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 2107: The application server delivers the cross certificate or cross certificate information to the user.
如图 22 所示,步骤 2201 ,本地 MME 接收用户上发的确定的 CA ; As shown in FIG. 22, in step 2201, the local MME receives the determined CA sent by the user;
步骤 2202 ,本地 CBE 接收本地 MME 转发的确定的 CA ; Step 2202: The local CBE receives the determined CA forwarded by the local MME.
步骤 2203 ,本地 CBE 转发本地 CBE 确定的 CA ;; Step 2203: The local CBE forwards the CA determined by the local CBE;
步骤 2204 ,本地 CA 判断是否已保存 CBE 下发的 CA 的交叉证书; Step 2204: The local CA determines whether the cross-certificate of the CA delivered by the CBE is saved.
步骤 2205 ,若未保存,则本地 CA 获取确定的 CA 的交叉证书; Step 2205: If not saved, the local CA obtains the cross-certificate of the determined CA;
步骤 2206 ,本地 CA 下发交叉证书或者交叉证书的信息到用户; Step 2206: The local CA sends the cross-certificate or cross-certificate information to the user.
或者采用 Or adopt
步骤 2207 ,本地 CA 上发获取的交叉证书到应用服务器; Step 2207: The local CA sends the obtained cross certificate to the application server.
步骤 2208 ,所述应用服务器下发交叉证书或者交叉证书的信息到用户。 Step 2208: The application server sends the cross-certificate or cross-certificate information to the user.
本发明实施例提供一种获取公钥的方法,所述方法通过用户上报全球 CA 列表或者确定的 CA ,本地
CA 根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书,或者确定的 CA 的交叉证书,所述本地 CA
将获取的交叉证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个 CA 下发给本地
CBE 的交叉证书或隐式证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 An embodiment of the present invention provides a method for obtaining a public key, where the method reports a global CA list or a determined CA, and the local
The CA obtains a cross-certificate of any one of the global CA lists according to the global list or the determined CA, or a cross-certificate of the determined CA, the local CA
The obtained cross-certificate is delivered to the user, so that the user can calculate the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be sent to the local through any CA in the CA list.
The CBE's cross-certificate or implicit certificate is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
实施例五 Embodiment 5
参考图 23 是本发明实施例五提供的一种获取公钥的方法流程图。如图所示, FIG. 23 is a flowchart of a method for obtaining a public key according to Embodiment 5 of the present invention. as the picture shows,
步骤 2301 ,判断本地网元是否存储本地 CBE 的公钥和 / 或本地 CA 的公钥; Step 2301: Determine whether the local network element stores the public key of the local CBE and/or the public key of the local CA.
步骤 2302 ,若是,则将所述本地 CBE 的公钥和 / 或本地 CA
的公钥下发给用户。 Step 2302, if yes, then the local CBE public key and / or local CA
The public key is sent to the user.
具体参考图 24 、图 25 、图 26 的方法示意图。如图 24 、图 25 、图 26
是本发明实施例五提供的一种获取公钥的方法示意图。 Refer to the schematic diagrams of Figure 24, Figure 25, and Figure 26. Figure 24, Figure 25, Figure 26
It is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
如图 24 所示,步骤 2401 ,本地 MME 判断是否存储本地 CA 的公钥和 / 或本地
CBE 的公钥; As shown in Figure 24, in step 2401, the local MME determines whether to store the local CA's public key and/or local.
The public key of the CBE;
步骤 2402 ,若是,则本地 MME 下发本地 MME 保存的 CA 的公钥和 / 或 CBE
的公钥。 Step 2402, if yes, the local MME sends the public key and/or CBE of the CA saved by the local MME.
Public key.
如图 25 所示,步骤 2501 ,本地 CBE 判断本地 CBE 是否保存本地 CBE 的公钥和
/ 或本地 CA 的公钥; As shown in Figure 25, in step 2501, the local CBE determines whether the local CBE saves the public key of the local CBE and
/ or the public key of the local CA;
步骤 2502 ,若是,则本地 CBE 下发本地 CBE 保存的 CA 的公钥和 / 或 CBE
的公钥。 Step 2502, if yes, the local CBE delivers the public key and/or CBE of the CA saved by the local CBE.
Public key.
如图 26 所示,步骤 2601 ,本地 CA 判断本地 CA 是否保存本地 CA 的公钥或者本地
CBE 的公钥; As shown in Figure 26, in step 2601, the local CA determines whether the local CA saves the local CA's public key or local.
The public key of the CBE;
步骤 2602 ,若保存,则本地 CA 下发本地 CA 保存的 CA 的公钥和 / 或 CBE
的公钥。 Step 2602: If saved, the local CA sends the public key and/or CBE of the CA saved by the local CA.
Public key.
本发明实施例提供一种获取公钥的方法,所述方法通过获取本地网元存储的本地 CA 的公钥或者本地
CBE 的公钥,并将所述获取的 CA 的公钥或者本地 CBE 的公钥下发给用户,使得用户根据所述 CA 的公钥或者本地 CBE 的公钥验证本地 CBE
下发的隐式证书。 An embodiment of the present invention provides a method for obtaining a public key, where the method obtains a public key of a local CA stored by a local network element or a local
The public key of the CBE and the public key of the obtained CA or the public key of the local CBE are sent to the user, so that the user verifies the local CBE according to the public key of the CA or the public key of the local CBE.
An implicit certificate issued.
实施例六 Embodiment 6
参考图 27 ,图 27 是本发明实施例六提供的一种获取公钥的方法流程图。如图 27
所示,所述方法包括如下步骤: Referring to FIG. 27, FIG. 27 is a flowchart of a method for obtaining a public key according to Embodiment 6 of the present invention. Figure 27
As shown, the method includes the following steps:
步骤 2701 ,用户将全球 CA 列表或者确定的 CA 信息上报给所述网元; Step 2701: The user reports the global CA list or the determined CA information to the network element.
本步骤中,所述网元包括: In this step, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSC 或 SGSN ,或者是 CBC 节点。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
步骤 2702 ,
所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书计算出 CBE 的公钥,并根据所述计算的 CBE
的公钥对本地 CBE 下发给用户的 PWS 消息进行验证。 Step 2702,
Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and calculating a public key of the CBE according to the cross certificate or the implicit certificate, and calculating according to the CBE
The public key verifies the PWS message sent to the user by the local CBE.
可优选的,所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA
的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述
PWS 消息的签名。
Preferably, the user receives the cross certificate issued by the network element, or the information of the cross certificate, and calculates the local CA according to the cross certificate and the public key of one CA in the global CA corresponding to the cross certificate.
The public key of the local CA is calculated according to the calculated public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
The signature of the PWS message.
可优选的,所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE
的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。
Preferably, the user receives an implicit certificate issued by the network element, or information of the implicit certificate, according to the implicit certificate and a CA of the global CA corresponding to the implicit certificate. Key calculation local CBE
The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
进一步,所述方法还包括: Further, the method further includes:
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE
公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。 Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE
The PWS message delivered by the local CBE is verified by the public key and / or the local CA public key.
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE
公钥或者本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证具体为: Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE
The PWS message delivered by the local CBE is verified by the public key or the local CA public key.
当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE
下发的 PWS 消息; When the user receives the local CBE public key delivered by the network element, the local CBE is directly verified according to the local CBE public key.
PWS message delivered;
当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE 下发的
PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。 When the user receives the local CA public key delivered by the network element, the local CA public key and the local CBE are delivered according to the local CA key
The implicit certificate in the PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
本发明实施例提供的一种获取公钥的方法,所述方法通过用户获取本地网元下发的交叉证书或者隐式证书,根据所述交叉证书或隐式证书计算本地 CA 的公钥或者本地 CBE
的公钥,并根据计算出的本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的 PWS 消息。
A method for obtaining a public key is provided by the embodiment of the present invention. The method obtains a cross certificate or an implicit certificate issued by a local network element, and calculates a public key or a local CA of the local CA according to the cross certificate or the implicit certificate. CBE
The public key is used to verify the PWS message sent by the local CBE to the user based on the calculated public key of the local CA or the public key of the local CBE.
实施例七 Example 7
参考图 28 ,图 28 是本发明实施例七提供的一种网元的装置结构图。如图 28
所示,所述网元包括如下单元: Referring to FIG. 28, FIG. 28 is a structural diagram of a device of a network element according to Embodiment 7 of the present invention. Figure 28
As shown, the network element includes the following units:
接收单元 2801 ,用于网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA
信息; The receiving unit 2801 is configured to receive, by the network element, a global authentication and authorization center CA list or a determined CA reported by the user.
Information
本单元中,所述网元包括: In this unit, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSC 或 SGSN ,或者是 CBC 节点。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
当用户附着到漫游网络,并且可选的用户没有预先存储所述漫游网络的本地 CA 或本地 CBE
的公钥时,无法对本地 CBE 下发的 PWS 消息或者其他消息进行验证。如果全球 CA 之间建立互信关系,则说明用户对 PWS 消息的认证可以通过 CA
之间的信任实现。因此,如果 UE 漫游到一种部署了 CAX 的特殊网络,为了实现 PWS 消息的认证,可以通过
CAX 与 CA1 之间建立安全关联并使得 CAX 获得 CA1 的交叉证书。交叉证书是 CA
之间互相签发的一种证书。其中, CAx 为用户漫游的网络部署自己网络的 CA ,不属于规划的全球 CA 范围内; CA1 属于全球 CA
范围,是用户预配置的全球 CA 之一。When a user attaches to a roaming network, and the optional user does not pre-store the public key of the local CA or the local CBE of the roaming network, the PWS message or other message delivered by the local CBE cannot be verified. If a mutual trust relationship is established between global CAs, the user's authentication of PWS messages can be achieved through trust between CAs. Therefore, if the UE roams to a special network where CA X is deployed, in order to authenticate the PWS message, a security association can be established between CA X and CA1 and CA X can obtain the cross-certificate of CA1. A cross-certificate is a certificate issued between CAs. Among them, CAx deploys its own network CA for the user roaming network, which is not within the planned global CA scope; CA1 belongs to the global CA scope and is one of the user-preconfigured global CAs.
如果 CA 之间没有建立互信关系,则 CAx 需要向 CA1
建立互信关系,获取交叉证书。否则,如果无法建立互信关系, CA1 会将无法验证本地 CBE 下发的 PWS 消息,无法告知用户 PWS
的安全性,此时将由用户决定是否继续信息本地 CBE 下发的 PWS 报警消息。 If there is no mutual trust between the CAs, CAx needs to go to CA1.
Establish a mutual trust relationship and obtain a cross-certificate. Otherwise, if the mutual trust relationship cannot be established, CA1 will not be able to verify the PWS message delivered by the local CBE, and cannot inform the user of PWS.
Security, at this time, the user will decide whether to continue the PWS alarm message sent by the local CBE.
获取单元 2802 ,用于当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA
时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; The obtaining unit 2802 is configured to: when the local CA is not in the global CA list or the local CA is not the determined CA
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
本单元中,所述可选的用户可以将全球 CA 列表或者确定的 CA
信息上报给所述漫游网络,即本地网络的网元,使得本地网元根据所述全球 CA 列表或者确定的 CA 信息判断本地网络是否预先存储所述全球 CA 列表中任意一个
CA 的交叉证书或者隐式证书,或者本地网络是否预先存储所述确定的 CA
信息中的交叉证书或者隐式证书。若本地网元已存,则直接下发给用户;若本地网元未存,则本地网元获取所述全球列表中任意一个 CA 的交叉证书或者获取所述确定的 CA
的交叉证书。 In this module, the optional user can list the global CA or determine the CA.
The information is reported to the roaming network, that is, the network element of the local network, so that the local network element determines, according to the global CA list or the determined CA information, whether the local network pre-stores any one of the global CA lists.
Cross-certificate or implicit certificate of the CA, or whether the local network pre-stores the determined CA
A cross-certificate or an implicit certificate in the message. If the local network element is saved, the local network element is directly sent to the user; if the local network element is not stored, the local network element obtains a cross certificate of any one of the global lists or obtains the determined CA.
Cross certificate.
第一下发单元 2803
,用于所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA
的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。 First delivery unit 2803
And the cross-certificate or the implicit certificate to be obtained by the network element, or the information of the cross-certificate or the implicit certificate obtained by the network element is sent to the user, so that the user according to the cross-certificate or the implicit certificate Calculate the local CA
The public key or the public key of the local cell broadcast entity CBE, and enable the user to verify the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
本单元中,所述交叉证书的信息可以是交叉证书的地址或信息等信息,所述交叉证书的信息使得用户根据所述交叉证书的信息获取交叉证书。当所述网元将获取的交叉证书或者获得交叉证书信息下发给用户时,用户根据交叉证书和交叉证书对应的全球
CA 列表中的某一个特定 CA 的公钥,计算出本地 CA 的公钥,根据本地 CA 的公钥和本地 CBE 下发给用户的 PWS 消息中的隐式证书计算出本地
CBE 的公钥,所述用户根据所述本地 CBE 的公钥对本地 CBE 下发给用户的 PWS 消息进行验证,从而识别接收的 PWS
消息是否是合法的公共报警信息。
In this unit, the information of the cross-certificate may be information such as the address or information of the cross-certificate, and the information of the cross-certificate enables the user to obtain the cross-certificate according to the information of the cross-certificate. When the network element sends the obtained cross-certificate or the obtained cross-certificate information to the user, the user corresponds to the cross-certificate and the cross-certificate corresponding to the global
The public key of a specific CA in the CA list, the public key of the local CA is calculated, and the local key is calculated according to the public key of the local CA and the implicit certificate in the PWS message sent to the user by the local CBE.
The public key of the CBE, the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE, thereby identifying the received PWS
Whether the message is a legitimate public alarm message.
本单元中,所述隐式证书的信息可以是隐式证书的地址或信息等信息,所述隐式证书的信息使得用户根据所述隐式证书的信息获取隐式证书。所述网元将获取的隐式证书或者获取隐式证书的信息下发给用户时,用户根据所述隐式证书和隐式证书对应的全球
CA 列表中的某一个特定 CA 的公钥,计算出本地 CBE 的公钥,根据本地 CBE 的公钥对本地 CBE 下发给用户的 PWS 消息进行验证,从而识别接收的
PWS 消息是否是合法的公共报警信息。
In this unit, the information of the implicit certificate may be information such as an address or information of an implicit certificate, and the information of the implicit certificate enables the user to obtain an implicit certificate according to the information of the implicit certificate. When the network element sends the obtained implicit certificate or the information for obtaining the implicit certificate to the user, the user corresponds to the global certificate corresponding to the implicit certificate and the implicit certificate.
The public key of a specific CA in the CA list, the public key of the local CBE is calculated, and the PWS message sent by the local CBE to the user is verified according to the public key of the local CBE, thereby identifying the received
Whether the PWS message is a legitimate public alarm message.
为了减少宽带,在所述网元获取的交叉证书或隐式证书时,可以选择下发所述交叉证书的链接或者地址等信息,或者选择下发所述隐式证书的链接或者地址等信息。
In order to reduce the bandwidth, the cross-certificate or the implicit certificate obtained by the network element may be selected to send the information such as the link or address of the cross-certificate, or the link or address to which the implicit certificate is issued.
进一步,所述网元还包括上发单元 2804 ,用于: Further, the network element further includes a sending unit 2804, configured to:
所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述应用服务器将所述交叉证书的或隐式证书的信息下发给用户,使得用户到对应的下载服务器下载交叉证书或隐式证书,并根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息。
The network element sends the obtained cross-certificate or implicit certificate to the application server, where the cross-certificate or the implicit certificate is used by the application server, or the application server uses the cross-certificate or the implicit certificate. The information is sent to the user, so that the user downloads a cross certificate or an implicit certificate to the corresponding download server, and calculates the local area according to the cross certificate or the implicit certificate.
The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message.
其中,所述应用服务器将所述交叉证书的或隐式证书的信息下发给用户,所述信息包括但不限于交叉证书的或隐式证书的信息的链接或地址。
The application server sends the information of the cross-certificate or the implicit certificate to the user, where the information includes, but is not limited to, a link or address of the information of the cross-certificate or the implicit certificate.
进一步,所述网元还包括第二下发单元 2805 : Further, the network element further includes a second sending unit 2805:
当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE
的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。 When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly uses the local CBE
The public key or the public key of the local CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
本发明实施例提供一种网元,所述网元通过用户上报全球 CA 列表或者确定的 CA
,本地网元根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书或者隐式证书,或者确定的 CA
的交叉证书或者隐式证书,所述网元将获取的交叉证书或者隐式证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过
CA 列表内的任意一个 CA 下发给本地网元的交叉证书或者隐式证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS
消息的目的。 An embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA by using a user.
And obtaining, by the local network element, a cross certificate or an implicit certificate of any one of the global CA lists according to the global list or the determined CA, or determining the CA
The cross-certificate or the implicit certificate, the network element sends the obtained cross-certificate or the implicit certificate to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, by
A cross-certificate or an implicit certificate that is sent to the local NE by any CA in the CA list, and the public key of the local network element CBE is calculated, so as to verify the PWS sent to the user by the local CBE.
The purpose of the message.
实施例八 Example eight
参考图 29 ,图 29 是本发明实施例八提供的一种网元的装置结构图。如图 29
所示,所述网元包括如下单元: Referring to FIG. 29, FIG. 29 is a structural diagram of a device of a network element according to Embodiment 8 of the present invention. Figure 29
As shown, the network element includes the following units:
第一接收单元 2901 ,用于所述本地核心网实体接收用户上报的全球认证授权中心 CA
列表或者确定的 CA 信息; The first receiving unit 2901 is configured to receive, by the local core network entity, a global authentication and authorization center CA reported by the user.
List or determined CA information;
可优选的,所述本地核心网实体接收用户上报的全球 CA 列表,参考图 3 的步骤 301 和图 4
的步骤 401 。 Preferably, the local core network entity receives the global CA list reported by the user, referring to step 301 and FIG. 4 of FIG.
Steps 401.
可优选的,所述本地核心网实体接收用户上报的确定的 CA 信息,参考图 5 的步骤 501 和图 6
的步骤 601 。 Preferably, the local core network entity receives the determined CA information reported by the user, referring to step 501 and FIG. 6 of FIG.
Steps 601.
第一获取单元 2902 ,用于当本地 CA 不在所述全球 CA 列表中或者不是确定的 CA
时,则所述本地核心网实体获取所述全球 CA 列表中任意一个 CA 的交叉证书或者确定的 CA 的交叉证书; The first obtaining unit 2902 is configured to: when the local CA is not in the global CA list or is not a determined CA
And obtaining, by the local core network entity, a cross certificate of any one of the global CA lists or a cross certificate of the determined CA;
可优选的,所述本地核心网实体接收用户上报的全球 CA 列表,当本地 CA 不在所述全球 CA
列表中时,且当所述本地核心网实体中存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接从本地核心网实体中获取所述本地核心网实体存储的所述任意一个
CA 的交叉证书。参考图 3 的步骤 302 。 Preferably, the local core network entity receives a global CA list reported by the user, when the local CA is not in the global CA.
When the list is in the list, and when the cross-certificate of any one of the global CA lists is stored in the local core network entity, the any one of the local core network entities stored is directly obtained from the local core network entity.
CA's cross-certificate. Refer to step 302 of Figure 3.
可优选的,当所述本地核心网实体中未存储所述全球 CA 列表中任意一个 CA
的交叉证书时,则从所述全球 CA 列表中选取任意一个 CA ,所述本地核心网实体获取所述选取的任意一个 CA 的交叉证书。参考图 4 的步骤 402 和步骤
403 。 Preferably, when the local core network entity does not store any one of the global CA lists
When the cross-certificate is obtained, any CA is selected from the global CA list, and the local core network entity obtains the cross-certificate of the selected one of the CAs. Refer to step 402 and steps in Figure 4.
403.
可优选的,所述本地核心网实体接收用户上报的确定的 CA 信息,当所述本地 MME 存储所述确定的
CA 的交叉证书时,则直接从本地核心网实体中获取所述本地核心网实体存储的所述确定的 CA 的交叉证书。参考图 5 的步骤 502 。 Preferably, the local core network entity receives the determined CA information reported by the user, when the local MME stores the determined
When the CA cross-certifies, the cross-certificate of the determined CA stored by the local core network entity is obtained directly from the local core network entity. Refer to step 502 of Figure 5.
可优选的,当所述本地核心网实体没有存储所述确定的 CA 的交叉证书时,则从所述确定的 CA
中获取所述确定的 CA 的交叉证书。参考图 6 的步骤 602 和步骤 603 。 Preferably, when the local core network entity does not store the cross-certificate of the determined CA, then the determined CA is obtained.
Obtaining the cross-certificate of the determined CA. Refer to step 602 and step 603 of Figure 6.
第三下发单元 2903
,用于所述本地核心网实体将获取的交叉证书,或者所述本地核心网实体将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证所述本地 CBE 下发给用户的 PWS 消息。 Third delivery unit 2903
And sending, to the user, the cross-certificate to be obtained by the local core network entity, or the information about the cross-certificate obtained by the local core network entity, so that the user calculates the local CA according to the cross-certificate
The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA.
本单元中,所述本地 MME 将获取的交叉证书下发给用户,具体参考图 3 的步骤 303 、图 4
的步骤 404 、图 5 的步骤 503 、图 6 的步骤 604 ; In this unit, the local MME sends the obtained cross-certificate to the user. For details, refer to step 303 and Figure 4 in Figure 3.
Step 404, step 503 of FIG. 5, step 604 of FIG. 6;
可优选的,所述本地核心网实体将获取的交叉证书的信息下发给用户,具体参考图 3 的步骤 303 、图
4 的步骤 404 、图 5 的步骤 503 、图 6 的步骤 604 。 Preferably, the local core network entity sends the obtained information of the cross-certificate to the user. For details, refer to step 303 and Figure 3 of Figure 3.
Step 404 of Figure 4, step 503 of Figure 5, and step 604 of Figure 6.
进一步,所述网元还包括第一上发单元 2904 ,所述第一上发单元用于: Further, the network element further includes a first sending unit 2904, where the first sending unit is used to:
所述核心网实体将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户获得所述交叉证书并根据所述交叉证书计算所述本地
CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。 具体参考图 3 的步骤 304 和步骤 305
,图 4 的步骤 405 和步骤 406 ,图 5 的步骤 504 和步骤 505 ,图 6 的步骤 605 和步骤 606 。
The core network entity sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the information of the cross-certificate to the user, so that the user obtains the cross-certificate and according to the Cross certificate calculation for the local
The public key of the CA, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA. Refer specifically to step 304 and step 305 of Figure 3.
Step 405 and step 406 of Fig. 4, step 504 and step 505 of Fig. 5, step 605 and step 606 of Fig. 6.
本发明实施例提供一种网元,所述网元通过用户上报全球 CA 列表或者确定的 CA ,本地 MME
根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书,或者确定的 CA 的交叉证书,所述本地 MME
将获取的交叉证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个 CA
下发给本地网元的交叉证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 The embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA, a local MME by using a user.
Obtaining, according to the global list or the determined CA, a cross-certificate of any one of the global CA lists, or a cross-certificate of the determined CA, the local MME
The obtained cross-certificate is delivered to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
The cross-certificate sent to the local NE is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
实施例九 Example nine
参考图 30 ,图 30 是本发明实施例九提供的一种网元的装置结构图,如图 29
所示,所述网元包括如下单元: Referring to FIG. 30, FIG. 30 is a structural diagram of a network element provided by Embodiment 9 of the present invention, as shown in FIG.
As shown, the network element includes the following units:
第二接收单元 3001 ,所述本地 CBE 接收所述本地核心网实体下发的全球认证授权中心 CA
列表或者确定的 CA 信息; The second receiving unit 3001, the local CBE receives the global authentication and authorization center CA delivered by the local core network entity.
List or determined CA information;
可优选的,所述本地 CBE 接收所述本地核心网实体转发的全球 CA 列表,所述核心网实体将全球
CA 列表直接转发给本地 CBE 。具体参考图 8 的步骤 801 和步骤 802 和图 9 的步骤 901 和步骤 902 。 Preferably, the local CBE receives a global CA list forwarded by the local core network entity, and the core network entity will be global
The CA list is forwarded directly to the local CBE. Refer specifically to steps 801 and 802 of Figure 8 and steps 901 and 902 of Figure 9.
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
可优选的,所述 MME 从所述全球 CA 列表中选取任意一个 CA ,并将所述选取的任意一个 CA
下发给本地 CBE 。具体参考图 10 的步骤 1001 和步骤 1002 和图 11 的步骤 1101 和步骤 1102 。 Preferably, the MME selects any CA from the global CA list, and selects any one of the selected CAs.
Issued to the local CBE. Refer specifically to steps 1001 and 1002 of Figure 10 and steps 1101 and 1102 of Figure 11.
可优选的,所述本地 CBE 接收所述本地 MME 转发的确定的 CA 信息。具体参考图 12
的步骤 1201 和步骤和图 13 的步骤 1301 和步骤 1302 。 Preferably, the local CBE receives the determined CA information forwarded by the local MME. Refer to Figure 12 for details.
Steps 1201 and steps and steps 1301 and 1302 of Figure 13.
第二获取单元 3002 ,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA
时,则所述本地 CBE 获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; a second obtaining unit 3002, when the local CA is not in the CA list or the local CA is not the determined CA
And obtaining, by the local CBE, a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
可优选的,当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 存储所述全球 CA
列表中任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书。具体参考图 8 的步骤 803 。 Preferably, when the local CBE obtains the global CA list, and when the local CBE stores the global CA
When an implicit certificate of any CA in the list is obtained, the implicit certificate of any one of the CAs is obtained directly from the local CBE. Refer to step 803 of Figure 8 for details.
可优选的,当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 未存储所述全球
CA 列表中任意一个 CA 的隐式证书时,则所述本地 CBE 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA
的交叉证书。具体参考图 9 的步骤 903 和步骤 904 。 Preferably, when the local CBE obtains the global CA list, and when the local CBE does not store the global
When an implicit certificate of any one of the CAs in the CA list is selected, the local CBE selects any CA from the global CA list and obtains any CA selected.
Cross certificate. Refer specifically to steps 903 and 904 of Figure 9.
可优选的,当本地 CBE 获取的是所述 MME 从所述全球 CA 列表中选取的任意一个 CA
时,并且当所述本地 CBE 存储所述 MME 选取的任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书。具体参考图 10
的步骤 1003 。 Preferably, when the local CBE obtains any one of the CAs selected by the MME from the global CA list
And when the local CBE stores an implicit certificate of any one of the CAs selected by the MME, the implicit certificate of the any one of the CAs is directly obtained from the local CBE. Refer to Figure 10 for details.
Step 1003.
可优选的,当本地 CBE 获取的是所述 MME 从所述全球 CA 列表中选取的任意一个 CA
时,并且当所述本地 CBE 未存储所述 MME 选取的任意一个 CA 的隐式证书时,则所述本地 CBE 中获取所述任意一个 CA 的交叉证书。具体参考图 11
的步骤 1103 和步骤 1104 。 Preferably, when the local CBE obtains any one of the CAs selected by the MME from the global CA list
And when the local CBE does not store the implicit certificate of any one of the CAs selected by the MME, the cross-certificate of the any one of the CAs is obtained in the local CBE. Refer to Figure 11 for details.
Steps 1103 and 1104.
可优选的,当所述本地 CBE 接收所述本地 MME 转发的确定的 CA 信息,并且当本地 CBE
存储所述确定的 CA 的隐式证书时,则直接从本地 CBE 中获取所述确定的 CA 的隐式证书。具体参考图 12 的步骤 1203 。 Preferably, when the local CBE receives the determined CA information forwarded by the local MME, and when the local CBE
When the implicit certificate of the determined CA is stored, the implicit certificate of the determined CA is obtained directly from the local CBE. Refer specifically to step 1203 of Figure 12.
可优选的,当所述本地 CBE 接收所述本地 MME 转发的确定的 CA 信息,且当本地 CBE
未存储所述确定的 CA 的隐式证书时,则获取所述确定的 CA 的交叉证书。具体参考图 13 的步骤 1303 和步骤 1304 。 Preferably, when the local CBE receives the determined CA information forwarded by the local MME, and when the local CBE
When the implicit certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer to step 1303 and step 1304 of Figure 13 for details.
第二上发单元 3003 ,用于所述本地 CBE 将获取的交叉证书或者隐式证书,或者所述 CBE
将获取的交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE
的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。 a second sending unit 3003, configured to use the cross certificate or implicit certificate that the local CBE will acquire, or the CBE
And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate.
The public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
可优选的,所述本地 CBE 将获取的交叉证书或者隐式证书下发给用户,具体参考图 8 的步骤 804
、图 9 的步骤 905 、图 10 的步骤 1004 、图 11 的步骤 1105 、图 12 的步骤 1204 、图 13 的步骤 1305 。 Preferably, the local CBE sends the obtained cross-certificate or the implicit certificate to the user. For details, refer to step 804 of FIG.
Step 905 of Fig. 9, step 1004 of Fig. 10, step 1105 of Fig. 11, step 1204 of Fig. 12, and step 1305 of Fig. 13.
可优选的,所述本地 CBE 将获取的交叉证书的信息或者隐式证书下发给用户,具体参考图 8 的步骤
804 、图 9 的步骤 905 、图 10 的步骤 1004 、图 11 的步骤 1105 、图 12 的步骤 1204 、图 13 的步骤 1305
。 Preferably, the local CBE sends the obtained cross-certificate information or the implicit certificate to the user. For details, refer to the steps in Figure 8.
804, step 905 of FIG. 9, step 1004 of FIG. 10, step 1105 of FIG. 11, step 1204 of FIG. 12, and step 1305 of FIG.
.
实施例中, CBE 可以获得由 CBC 从所述全球 CA 列表中选取的任意一个 CA
,具体方法类似。 In an embodiment, the CBE can obtain any CA selected by the CBC from the global CA list.
The specific method is similar.
进一步,所述网元还包括第二上发单元 3004 : Further, the network element further includes a second sending unit 3004:
所述 CBE
将获取的交叉证书或者隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或者所述隐式证书,或者所述交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地
CA 的公钥,或者使得用户根据所述隐式证书计算所述本地 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE
下发用户的公共报警系统 PWS 消息。 具体参考图 8 的步骤 805 和步骤 806 ,图 9 的步骤 906 和步骤 907 ,图 10 的步骤 1005
和步骤 1006 ,图 11 的步骤 1106 和步骤 1107 ,图 12 的步骤 1205 和步骤 1206 ,图 13 的步骤 1306 和步骤
1307 。 The CBE
Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user. Causing a user to calculate the local based on the cross-certificate
The public key of the CA, or causing the user to calculate the public key of the local CBE according to the implicit certificate, and causing the user to verify the local CBE according to the public key of the local CA or the public key of the local CBE
The user's public alarm system PWS message is delivered. Referring specifically to step 805 and step 806 of FIG. 8, step 906 and step 907 of FIG. 9, step 1005 of FIG.
And step 1006, step 1106 and step 1107 of FIG. 11, step 1205 and step 1206 of FIG. 12, step 1306 and step of FIG.
1307.
本发明实施例提供一种网元,所述网元通过用户上报全球 CA 列表或者确定的 CA ,本地 CBE
根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书,或者确定的 CA 的交叉证书或隐式证书,所述本地 CBE
将获取的交叉证书或隐式证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个 CA
下发给本地 CBE 的交叉证书或隐式证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 An embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA, a local CBE.
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists, or a cross-certificate or an implicit certificate of the determined CA, according to the global list or the determined CA, the local CBE
The obtained cross-certificate or implicit certificate is sent to the user, so that the user calculates the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be passed through any CA in the CA list.
A cross-certificate or an implicit certificate is sent to the local CBE to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
实施例十 Example ten
参考图 31 ,图 31 是本发明实施例十提供的一种网元的装置结构图,如图 30
所示,所述网元包括如下单元: Referring to FIG. 31, FIG. 31 is a structural diagram of a network element provided by Embodiment 10 of the present invention, as shown in FIG.
As shown, the network element includes the following units:
第三接收单元 3101 ,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的
CA 信息; The third receiving unit 3101, the local CA receives the list of global certification authority CAs reported by the user or determines
CA information;
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
可优选的,所述本地 MME 接收用户上报的所述全球 CA 列表,将所述全球 CA
列表转发给所述本地 CBE ,由所述本地 CBE 将所述全球 CA 列表转发给所述本地 CA 。具体参考图 15 的步骤 1501 和步骤 1502 和步骤
1503 ,和图 16 的步骤 1601 和步骤 1602 和步骤 1603 。 Preferably, the local MME receives the global CA list reported by the user, and the global CA is
The list is forwarded to the local CBE, and the global CA list is forwarded by the local CBE to the local CA. Refer specifically to step 1501 and step 1502 and steps in Figure 15.
1503, and step 1601 and step 1602 and step 1603 of Figure 16.
可优选的,所述本地 MME 接收用户上报的所述全球 CA 列表,将所述全球 CA
列表转发给所述本地 CBE ,由所述本地 CBE 从所述全球 CA 列表中选取任意一个 CA ,并将选取的任意一个 CA 上报给所述本地 CA 。具体参考
17 的步骤 1701 和步骤 1702 和步骤 1703 ,和图 18 的步骤 1801 和步骤 1802 和步骤 1803 。 Preferably, the local MME receives the global CA list reported by the user, and the global CA is
The list is forwarded to the local CBE, and the local CBE selects any CA from the global CA list, and reports any selected CA to the local CA. Specific reference
Step 17 of step 1701 and step 1702 and step 1703, and step 1801 of step 18 and step 1802 and step 1803.
可优选的,所述本地 MME 接收用户上报的所述全球 CA 列表,由所述本地 MME 从所述全球
CA 列表中选取任意一个 CA ,并将所述本地 MME 选取的任意一个 CA 上报给本地 CBE ,由所述本地 CBE 将所述本地 MME 选取的任意一个
CA 上报转发给所述本地 CA 。具体参考图 19 的步骤 1901 和步骤 1902 和步骤 1903 ,和图 20 的步骤 2001 和步骤 2002
和步骤 2003 。 Preferably, the local MME receives the global CA list reported by the user, and the local MME is from the global
Select any CA in the CA list, and report any CA selected by the local MME to the local CBE, and the local CBE selects any one of the local MMEs.
The CA report is forwarded to the local CA. Refer specifically to step 1901 and steps 1902 and 1903 of Figure 19, and steps 2001 and 2002 of Figure 20
And steps 2003.
可优选的,所述本地 MME 接收用户上报的所述确定的 CA 信息,所述 MME 将所述确定的 CA
信息转发给所述本地 CBE ,并由所述本地 CBE 将所述确定的 CA 信息转发给所述本地 CA 。具体参考 21 的步骤 2101 和步骤 2102 和步骤
2103 ,和图 22 的步骤步骤 2201 和步骤 2202 和步骤 2203 。 Preferably, the local MME receives the determined CA information reported by the user, and the MME determines the determined CA.
Information is forwarded to the local CBE, and the determined CA information is forwarded by the local CBE to the local CA. Refer to step 2101 and step 2102 and steps in step 21 for details.
2103, and step 22, step 2201 and step 2202 and step 2203 of FIG.
第三获取单元 3102 ,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA
时,则所述 CA 获取所述全球 CA 列表中任意一个 CA 的交叉证书;或者获取所述确定的 CA 的交叉证书; a third obtaining unit 3102, when the local CA is not in the CA list or the local CA is not the determined CA
And obtaining, by the CA, a cross-certificate of any one of the global CA lists; or obtaining a cross-certificate of the determined CA;
可优选的,当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 存储所述全球 CA
列表中任意一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意一个 CA 的交叉证书。具体参考图 15 的步骤 1504 。 Preferably, when the local CA acquires the global CA list, and when the local CA stores the global CA
When the cross-certificate of any CA in the list is obtained, the cross-certificate of any one of the CAs is obtained directly from the local CA. Refer specifically to step 1504 of Figure 15.
可优选的,当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 未存储所述全球 CA
列表中任意一个 CA 的交叉证书时,则所述本地 CA 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书。具体参考图
16 的步骤 1604 和步骤 1605 。 Preferably, when the local CA acquires the global CA list, and when the local CA does not store the global CA
When the cross-certificate of any one of the CAs in the list is selected, the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs. Specific reference map
Step 16 of step 16 and step 1605.
可优选的,当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA
时,并当本地 CA 存储所述任意选取的一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意选取的一个 CA 的交叉证书。具体参考图 17 的步骤
1704 。 Preferably, when the local CA obtains, the local CBE is arbitrarily selected from the global CA list.
And when the local CA stores the cross-certificate of the arbitrarily selected one of the CAs, the cross-certificate of the arbitrarily selected one of the CAs is obtained directly from the local CA. Refer specifically to the steps in Figure 17.
1704.
可优选的,当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA
时,并当本地 CA 未存储所述任意选取的一个 CA 的交叉证书时,则所述本地 CA 获取所述任意选取的一个 CA 的交叉证书。具体参考图 18 的步骤
1804 和步骤 1805 。 Preferably, when the local CA obtains, the local CBE is arbitrarily selected from the global CA list.
And when the local CA does not store the cross-certificate of the arbitrarily selected one of the CAs, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs. Refer specifically to the steps in Figure 18.
1804 and step 1805.
可优选的当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA
存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 直接从本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。具体参考图 19
的步骤 1904 。 Preferably, when the local CA receives any CA forwarded by the local CBE, and is a local CA
When the CA is forwarded by the local CBE, the local CA obtains the cross-certificate of any CA forwarded by the local CBE. Refer to Figure 19 for details.
Step 1904.
可优选的当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA
未存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。具体参考图 20 的步骤 2004
和步骤 2005 。 Preferably, when the local CA receives any CA forwarded by the local CBE, and is a local CA
When any CA of the local CBE forwarding is not stored, the local CA acquires a cross certificate of any CA forwarded by the local CBE. Refer specifically to the steps in Figure 20 2004
And steps 2005.
可优选的,当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA
存储所述确定的 CA 的交叉证书时,则直接从本地 CA 中获取所述确定的 CA 的交叉证书。具体参考图 21 的步骤 2104 。 Preferably, when the local CA receives the determined CA information forwarded by the local CBE, and when the local CA
When the cross-certificate of the determined CA is stored, the cross-certificate of the determined CA is obtained directly from the local CA. Refer specifically to step 2104 of Figure 21.
可优选的,当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA
未存储所述确定的 CA 的交叉证书,则获取所述确定的 CA 的交叉证书。具体参考图 22 的步骤 2204 和步骤 2205 。 Preferably, when the local CA receives the determined CA information forwarded by the local CBE, and when the local CA
If the cross-certificate of the determined CA is not stored, the cross-certificate of the determined CA is obtained. Refer specifically to step 2204 and step 2205 of Figure 22.
第七下发单元 3103 ,所述本地 CA 将获取的交叉证书,或者所述本地 CA
将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE
下发给用户的公共报警系统 PWS 消息。 a seventh sending unit 3103, the cross certificate obtained by the local CA, or the local CA
And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA.
A public alarm system PWS message that is sent to the user.
可优选的,所述本地 CA 将获取的交叉证书下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。具体参考图 15 的步骤 1505 ,图 16 的步骤 1606
,图 17 的步骤 1705 ,图 18 的步骤 1806 ,图 19 的步骤 1905 ,图 20 的步骤 2006 ,图 21 的步骤 2105 ,图
22 的步骤 2206 。 Preferably, the local CA sends the obtained cross certificate to the user, so that the user calculates the local CA according to the cross certificate.
The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16
Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig.
Step 2206 of 22.
可优选的,所述本地 CA 将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。具体参考图 15 的步骤 1505 ,图 16 的步骤 1606
,图 17 的步骤 1705 ,图 18 的步骤 1806 ,图 19 的步骤 1905 ,图 20 的步骤 2006 ,图 21 的步骤 2105 ,图
22 的步骤 2206 。 Preferably, the local CA sends the obtained cross-certificate information to the user, so that the user calculates the local CA according to the cross-certificate.
The public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA. Referring specifically to step 1505 of Figure 15, step 1606 of Figure 16
Step 1705 of Fig. 17, step 1806 of Fig. 18, step 1905 of Fig. 19, step 2006 of Fig. 20, step 2105 of Fig. 21, Fig.
Step 2206 of 22.
进一步,所述网元还包括第三上发单元 3104 : Further, the network element further includes a third sending unit 3104:
所述 CA
将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。 具体参考图 15 的步骤 1506 和步骤 1507
,图 16 的步骤 1607 和步骤 1607 ,图 17 的步骤 1706 和步骤 1707 ,图 18 的步骤 1807 和步骤 1808 ,图 19
的步骤 1906 和步骤 1907 ,图 20 的步骤 2007 和步骤 2008 ,图 21 的步骤 2106 和步骤 2107 ,图 22 的步骤
2207 和步骤 2208 。 The CA
The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate.
The public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA. Refer to steps 1506 and 1507 of Figure 15 for details.
Step 1607 and step 1607 of Fig. 16, step 1706 and step 1707 of Fig. 17, step 1807 and step 1808 of Fig. 18, Fig. 19
Steps 1906 and 1907, steps 20 and 20 of Figure 20, steps 2106 and 2107 of Figure 21, steps of Figure 22
2207 and step 2208.
本发明实施例提供一种网元,所述网元通过用户上报全球 CA 列表或者确定的 CA ,本地 CA
根据所述全球列表或者确定的 CA ,获取所述全球 CA 列表中任意一个 CA 的交叉证书,或者确定的 CA 的交叉证书,所述本地 CA
将获取的交叉证书下发给用户,使得用户计算出本地 CBE 的公钥,使得用户漫游到运营商部署的 CA 列表外时,可通过 CA 列表内的任意一个 CA 下发给本地
CBE 的交叉证书或隐式证书,计算出本地网元 CBE 的公钥,从而达到验证本地 CBE 下发给用户的 PWS 消息的目的。 An embodiment of the present invention provides a network element, where the network element reports a global CA list or a determined CA, a local CA.
Obtaining, according to the global list or the determined CA, a cross-certificate of any one of the global CA lists, or a cross-certificate of the determined CA, the local CA
The obtained cross-certificate is delivered to the user, so that the user can calculate the public key of the local CBE, so that when the user roams outside the CA list deployed by the operator, the CA can be sent to the local through any CA in the CA list.
The CBE's cross-certificate or implicit certificate is used to calculate the public key of the local network element CBE, so as to verify the PWS message sent by the local CBE to the user.
实施例十一 Embodiment 11
参考图 32 ,图 32 是本发明实施例十一提供的一种网元的装置结构图。如图 31
所示,所述网元包括如下单元: Referring to FIG. 32, FIG. 32 is a structural diagram of a device of a network element according to Embodiment 11 of the present invention. Figure 31
As shown, the network element includes the following units:
第四下发单元 3201 ,用于判断本地网元是否存储本地 CBE 的公钥和 / 或本地 CA
的公钥;若是,则将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户。 The fourth sending unit 3201 is configured to determine whether the local network element stores the public key of the local CBE and/or the local CA.
The public key; if so, the public key of the local CBE and/or the public key of the local CA are delivered to the user.
具体参考图 24 、图 25 、图 26 的方法示意图。如图 24 、图 25 、图 26
是本发明实施例五提供的一种获取公钥的方法示意图。 Refer to the schematic diagrams of Figure 24, Figure 25, and Figure 26. Figure 24, Figure 25, Figure 26
It is a schematic diagram of a method for obtaining a public key according to Embodiment 5 of the present invention.
本说明书中核心网实体均以 LTE 网络中的 MME 为例进行说明。 The core network entities in this manual use the MME in the LTE network as an example.
第六下发单元 3202 ,如图 25 所示,用于本地 CBE 判断本地 CBE 是否保存本地
CBE 的公钥和 / 或本地 CA 的公钥;若是,则本地 CBE 下发本地 CBE 保存的 CA 的公钥和 / 或 CBE 的公钥。 The sixth delivery unit 3202, as shown in FIG. 25, is used by the local CBE to determine whether the local CBE is saved locally.
The public key of the CBE and/or the public key of the local CA; if so, the local CBE delivers the public key of the CA saved by the local CBE and/or the public key of the CBE.
第八下发单元 3203 ,如图 26 所示,用于本地 CA 判断本地 CA 是否保存本地 CA
的公钥或者本地 CBE 的公钥;若保存,则本地 CA 下发本地 CA 保存的 CA 的公钥和 / 或 CBE 的公钥。 The eighth sending unit 3203, as shown in FIG. 26, is used by the local CA to determine whether the local CA saves the local CA.
The public key or the public key of the local CBE; if saved, the local CA issues the public key of the CA saved by the local CA and/or the public key of the CBE.
本发明实施例提供一种网元,所述网元通过获取本地网元存储的本地 CA 的公钥或者本地 CBE
的公钥,并将所述获取的 CA 的公钥或者本地 CBE 的公钥下发给用户,使得用户根据所述 CA 的公钥或者本地 CBE 的公钥验证本地 CBE
下发的隐式证书。 The embodiment of the present invention provides a network element, where the network element obtains a public key of a local CA or a local CBE stored by a local network element.
Public key, and the public key of the obtained CA or the public key of the local CBE is sent to the user, so that the user verifies the local CBE according to the public key of the CA or the public key of the local CBE.
An implicit certificate issued.
实施例十二 Example twelve
参考图 33 ,图 33 是本发明实施例十二提供的一种终端设备的装置结构图。如图 33
所示,所述终端设备包括如下单元: Referring to FIG. 33, FIG. 33 is a structural diagram of a device of a terminal device according to Embodiment 12 of the present invention. Figure 33
As shown, the terminal device includes the following units:
信息上报单元 3301 ,用于用户将全球 CA 列表或者确定的 CA 信息上报给所述网元; The information reporting unit 3301 is configured to report the global CA list or the determined CA information to the network element.
本单元中,所述网元包括: In this unit, the network element includes:
核心网节点, CBE , CA ; Core network node, CBE, CA
其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是
SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSC 或 SGSN ,或者是 CBC 节点。 The core network node in the LTE network, the network element entity is an MME, and in the UMTS network, the network element entity is
SGSN, in the GSM or GPRS network, the network element entity is an MSC or SGSN, or a CBC node.
接收验证单元 3302 ,用于
所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书计算出 CBE 的公钥,并根据所述计算的 CBE
的公钥对本地 CBE 下发给用户的 PWS 消息进行验证。 Receive verification unit 3302 for
Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and calculating a public key of the CBE according to the cross certificate or the implicit certificate, and calculating according to the CBE
The public key verifies the PWS message sent to the user by the local CBE.
可优选的,通过第一接收验证单元 3303
,所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA
的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述
PWS 消息的签名。 Preferably, the first receiving verification unit 3303 is passed
The user receives the cross-certificate issued by the network element, or the information of the cross-certificate, and calculates the local CA according to the cross-certificate and the public key of one CA in the global CA corresponding to the cross-certificate
The public key of the local CA is calculated according to the calculated public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, and the public key is verified according to the public key of the local CBE.
The signature of the PWS message.
可优选的,通过第二接收验证单元 3304
,所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE
的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。 Preferably, the second receiving verification unit 3304
And the user receives the implicit certificate sent by the network element, or the information of the implicit certificate, and calculates the locality according to the implicit certificate and a public key of a CA in the global CA corresponding to the implicit certificate. CBE
The user's public key, the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
进一步,所述终端设备还包括第三接收验证单元 3305 ,用于: Further, the terminal device further includes a third receiving verification unit 3305, configured to:
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE 公钥和
/ 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。 Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE public key and
/ or the local CA public key verifies the PWS message delivered by the local CBE.
所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE
公钥或者本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证具体为: Receiving, by the user, a local CBE public key and/or a local CA public key delivered by the network element, according to the local CBE
The PWS message delivered by the local CBE is verified by the public key or the local CA public key.
当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE
下发的 PWS 消息; When the user receives the local CBE public key delivered by the network element, the local CBE is directly verified according to the local CBE public key.
PWS message delivered;
当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE 下发的
PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。 When the user receives the local CA public key delivered by the network element, the local CA public key and the local CBE are delivered according to the local CA key
The implicit certificate in the PWS message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
本发明实施例提供的一种终端设备,所述终端设备通过用户获取本地网元下发的交叉证书或者隐式证书,根据所述交叉证书或隐式证书计算本地 CA 的公钥或者本地 CBE
的公钥,并根据计算出的本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的 PWS 消息。
A terminal device provided by the embodiment of the present invention, the terminal device obtains a cross certificate or an implicit certificate issued by a local network element, and calculates a public key or a local CBE of the local CA according to the cross certificate or the implicit certificate.
The public key is used to verify the PWS message sent by the local CBE to the user based on the calculated public key of the local CA or the public key of the local CBE.
实施例十三 Example thirteen
参考图 34 ,图 34 是本发明实施例十三提供的一种网元的装置结构图。参考图 34 ,图 34
是本发明实施例提供的一种网元 3400 ,本发明具体实施例并不对所述网络设备的具体实现做限定。所述设备 3400 包括: Referring to FIG. 34, FIG. 34 is a structural diagram of a device of a network element according to Embodiment 13 of the present invention. Refer to Figure 34, Figure 34
The network element 3400 is provided in the embodiment of the present invention. The specific implementation of the network device is not limited. The device 3400 includes:
处理器 (processor)3401 ,通信接口 (Communications
Interface)3402 ,存储器 (memory)3403 ,总线 3404 。 Processor 3401, communication interface (Communications)
Interface) 3402, memory 3403, bus 3404.
处理器 3401 ,通信接口 3402 ,存储器 3403 通过总线 3404
完成相互间的通信。 Processor 3401, communication interface 3402, memory 3403 through bus 3404
Complete communication with each other.
通信接口 3402 ,用于与其他网元进行通信; a communication interface 3402, configured to communicate with other network elements;
处理器 3401 ,用于执行程序 A 。 The processor 3401 is configured to execute the program A.
具体地,程序 A 可以包括程序代码,所述程序代码包括计算机操作指令。 In particular, program A may include program code, the program code including computer operating instructions.
处理器 3401 可能是一个中央处理器 CPU ,或者是特定集成电路 ASIC (
Application Specific Integrated Circuit ),或者是被配置成实施本发明实施例的一个或多个集成电路。 The processor 3401 may be a central processing unit CPU or a specific integrated circuit ASIC (
Application Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
存储器 3403 ,用于存放程序 A 。存储器 3303 可能包含高速 RAM
存储器,也可能还包括非易失性存储器( non-volatile memory )。程序 A 具体可以包括: The memory 3403 is used to store the program A. Memory 3303 may contain high speed RAM
The memory may also include a non-volatile memory. Program A can specifically include:
接收单元 2801 ,用于网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息; The receiving unit 2801 is configured to receive, by the network element, a global authentication and authorization center CA list or determined CA information reported by the user;
获取单元 2802 ,用于当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA
时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; The obtaining unit 2802 is configured to: when the local CA is not in the global CA list or the local CA is not the determined CA
Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
第一下发单元 2803
,用于所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA
的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息; First delivery unit 2803
And the cross-certificate or the implicit certificate to be obtained by the network element, or the information of the cross-certificate or the implicit certificate obtained by the network element is sent to the user, so that the user according to the cross-certificate or the implicit certificate Calculate the local CA
The public key or the public key of the local cell broadcast entity CBE, and enable the user to verify the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message
上发单元 2804
,用于:所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述应用服务器将所述交叉证书的或隐式证书的信息下发给用户,使得用户到对应的下载服务器下载交叉证书或隐式证书,并根据所述交叉证书或隐式证书计算所述本地
CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS
消息; Sendering unit 2804
And the network element sends the obtained cross-certificate or implicit certificate to the application server, where the cross-certificate or the implicit certificate is used by the application server, or the application server compares the cross-certificate or The information of the implicit certificate is sent to the user, so that the user downloads the cross certificate or the implicit certificate to the corresponding download server, and calculates the local according to the cross certificate or the implicit certificate.
The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE.
Message
第二下发单元 2805 ,用于当所述网元存储本地 CBE 的公钥或者本地 CA
的公钥时,则所述网元直接将所述本地 CBE 的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE
下发给用户的 PWS 消息; a second sending unit 2805, configured to: when the network element stores a public key of a local CBE or a local CA
If the public key is used, the network element directly sends the public key of the local CBE or the public key of the local CA to the user, so that the user verifies the local CBE according to the public key of the local CBE or the public key of the local CA.
PWS message sent to the user;
或者程序 A 具体可以包括: Or program A can specifically include:
第一接收单元 2901 ,用于所述本地核心网实体接收用户上报的全球认证授权中心 CA 列表或者确定的
CA 信息; The first receiving unit 2901 is configured to receive, by the local core network entity, a list of global authentication authority CAs reported by the user or determine
CA information;
第一获取单元 2902 ,用于当本地 CA 不在所述全球 CA 列表中或者不是确定的 CA
时,则所述本地核心网实体获取所述全球 CA 列表中任意一个 CA 的交叉证书或者确定的 CA 的交叉证书; The first obtaining unit 2902 is configured to: when the local CA is not in the global CA list or is not a determined CA
And obtaining, by the local core network entity, a cross certificate of any one of the global CA lists or a cross certificate of the determined CA;
第三下发单元 2903
,用于所述本地核心网实体将获取的交叉证书,或者所述本地核心网实体将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证所述本地 CBE 下发给用户的 PWS 消息; Third delivery unit 2903
And sending, to the user, the cross-certificate to be obtained by the local core network entity, or the information about the cross-certificate obtained by the local core network entity, so that the user calculates the local CA according to the cross-certificate
a public key, and the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CA;
第一上发单元 2904
,用于所述核心网实体将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户获得所述交叉证书并根据所述交叉证书计算所述本地
CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息; First sending unit 2904
And the core network entity sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the cross-certificate information to the user, so that the user obtains the cross-certificate and Calculating the local according to the cross certificate
The public key of the CA, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA;
或者程序 A 具体可以包括: Or program A can specifically include:
第二接收单元 3001 ,所述本地 CBE 接收所述本地核心网实体下发的全球认证授权中心 CA
列表或者确定的 CA 信息; The second receiving unit 3001, the local CBE receives the global authentication and authorization center CA delivered by the local core network entity.
List or determined CA information;
第二获取单元 3002 ,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA
时,则所述本地 CBE 获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书; a second obtaining unit 3002, when the local CA is not in the CA list or the local CA is not the determined CA
And obtaining, by the local CBE, a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA;
第五下发单元 3003 ,用于所述本地 CBE 将获取的交叉证书或者隐式证书,或者所述 CBE
将获取的交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE
的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息; a fifth sending unit 3003, configured to use the cross certificate or implicit certificate that the local CBE will obtain, or the CBE
And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate.
The public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE;
第二上发单元 3004 ,所述 CBE
将获取的交叉证书或者隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或者所述隐式证书,或者所述交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地
CA 的公钥,或者使得用户根据所述隐式证书计算所述本地 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE
下发用户的公共报警系统 PWS 消息; a second sending unit 3004, the CBE
Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user. Causing a user to calculate the local based on the cross-certificate
The public key of the CA, or causing the user to calculate the public key of the local CBE according to the implicit certificate, and causing the user to verify the local CBE according to the public key of the local CA or the public key of the local CBE
Deliver the user's public alarm system PWS message;
或者程序 A 具体可以包括: Or program A can specifically include:
第三接收单元 3101 ,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA
信息; The third receiving unit 3101, the local CA receives the global authentication authorization center CA list or the determined CA reported by the user.
Information
第三获取单元 3102 ,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA
时,则所述 CA 获取所述全球 CA 列表中任意一个 CA 的交叉证书;或者获取所述确定的 CA 的交叉证书; a third obtaining unit 3102, when the local CA is not in the CA list or the local CA is not the determined CA
And obtaining, by the CA, a cross-certificate of any one of the global CA lists; or obtaining a cross-certificate of the determined CA;
第七下发单元 3103 ,所述本地 CA 将获取的交叉证书,或者所述本地 CA
将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE
下发给用户的公共报警系统 PWS 消息; a seventh sending unit 3103, the cross certificate obtained by the local CA, or the local CA
And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA.
Public alarm system PWS message sent to the user;
第三上发单元 3104 ,所述 CA
将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA
的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息; a third sending unit 3104, the CA
The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate.
Public key, and enable the user to verify the public alarm system PWS message delivered by the local CBE according to the public key of the local CA;
或者程序 A 具体包括: Or program A specifically includes:
第四下发单元 3201 ,用于判断本地网元是否存储本地 CBE 的公钥和 / 或本地 CA
的公钥;若是,则将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户。 The fourth sending unit 3201 is configured to determine whether the local network element stores the public key of the local CBE and/or the local CA.
The public key; if so, the public key of the local CBE and/or the public key of the local CA are delivered to the user.
或者程序 A 具体包括: Or program A specifically includes:
第六下发单元 3202 ,用于本地 CBE 判断本地 CBE 是否保存本地 CBE 的公钥和 /
或本地 CA 的公钥;若是,则本地 CBE 下发本地 CBE 保存的 CA 的公钥和 / 或 CBE 的公钥。 The sixth sending unit 3202 is used by the local CBE to determine whether the local CBE saves the public key of the local CBE and /
Or the public key of the local CA; if so, the local CBE delivers the public key of the CA saved by the local CBE and/or the public key of the CBE.
或者程序 A 具体包括: Or program A specifically includes:
第八下发单元 3203 ,用于本地 CA 判断本地 CA 是否保存本地 CA 的公钥或者本地 CBE
的公钥;若保存,则本地 CA 下发本地 CA 保存的 CA 的公钥和 / 或 CBE 的公钥。 The eighth sending unit 3203 is configured to determine, by the local CA, whether the local CA saves the public key of the local CA or the local CBE.
The public key; if saved, the local CA issues the public key of the CA saved by the local CA and/or the public key of the CBE.
程序 A 中各单元的具体实现参见图 28 或图 29 或图 30 或图 31 或图 32
所示实施例中的相应单元,在此不赘述。 See Figure 28 or Figure 29 or Figure 30 or Figure 31 or Figure 32 for the specific implementation of each unit in Program A.
Corresponding units in the illustrated embodiment are not described herein.
实施例十四 Embodiment 14
参考图 35 ,图 35 是本发明实施例十四提供的一种终端设备的装置结构图。参考图 35 ,图 35
是本发明实施例提供的一种终端设备 3500 ,本发明具体实施例并不对所述网络设备的具体实现做限定。所述设备 3500 包括: Referring to FIG. 35, FIG. 35 is a structural diagram of a device of a terminal device according to Embodiment 14 of the present invention. Refer to Figure 35, Figure 35
The terminal device 3500 is provided in the embodiment of the present invention. The specific implementation of the network device does not limit the specific implementation of the network device. The device 3500 includes:
处理器 (processor)3501 ,通信接口 (Communications
Interface)3502 ,存储器 (memory)3503 ,总线 3504 。 Processor 3501, communication interface (Communications)
Interface) 3502, memory (3503), bus 3504.
处理器 3501 ,通信接口 3502 ,存储器 3503 通过总线 3504
完成相互间的通信。 Processor 3501, communication interface 3502, memory 3503 through bus 3504
Complete communication with each other.
通信接口 3502 ,用于与其他网元进行通信; a communication interface 3502, configured to communicate with other network elements;
处理器 3501 ,用于执行程序 A 。 A processor 3501 for executing program A.
具体地,程序 A 可以包括程序代码,所述程序代码包括计算机操作指令。 In particular, program A may include program code, the program code including computer operating instructions.
处理器 3501 可能是一个中央处理器 CPU ,或者是特定集成电路 ASIC (
Application Specific Integrated Circuit ),或者是被配置成实施本发明实施例的一个或多个集成电路。 The processor 3501 may be a central processing unit CPU or a specific integrated circuit ASIC (
Application Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.
存储器 3503 ,用于存放程序 A 。存储器 3503 可能包含高速 RAM
存储器,也可能还包括非易失性存储器( non-volatile memory )。程序 A 具体可以包括: The memory 3503 is used to store the program A. Memory 3503 may contain high speed RAM
The memory may also include a non-volatile memory. Program A can specifically include:
信息上报单元 3301 ,用于用户将全球 CA 列表或者确定的 CA 信息上报给所述网元; The information reporting unit 3301 is configured to report the global CA list or the determined CA information to the network element.
接收验证单元 3302 ,用于
所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书计算出 CBE 的公钥,并根据所述计算的 CBE
的公钥对本地 CBE 下发给用户的 PWS 消息进行验证。 Receive verification unit 3302 for
Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and calculating a public key of the CBE according to the cross certificate or the implicit certificate, and calculating according to the CBE
The public key verifies the PWS message sent to the user by the local CBE.
第三接收验证单元 3305 ,用于所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA
公钥,根据所述本地 CBE 公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。 The third receiving verification unit 3305 is configured to receive, by the user, the local CBE public key and/or the local CA delivered by the network element.
The public key authenticates the PWS message delivered by the local CBE according to the local CBE public key and/or the local CA public key.
程序 A 中各单元的具体实现参见图 33 所示实施例中的相应单元,在此不赘述。 For the specific implementation of each unit in the program A, refer to the corresponding unit in the embodiment shown in FIG. 33, and details are not described herein.
以上所述仅为本发明的优选实施方式,并不构成对本发明保护范围的限定。任何在本发明的精神和原则之内所作的任何修改、等同替换和改进等,均应包含在本发明要求包含范围之内。
The above is only a preferred embodiment of the present invention and is not intended to limit the scope of the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and scope of the invention are intended to be included within the scope of the invention.
Claims (98)
- 一种获取公钥的方法,所述方法包括:A method of obtaining a public key, the method comprising:网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息;The network element receives the global authentication authority CA list or the determined CA information reported by the user;当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书;Obtaining any CA in the global CA list when the local CA is not in the global CA list or the local CA is not the determined CA Cross-certificate or implicit certificate; or obtain a cross-certificate or an implicit certificate of the determined CA;所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The network element sends the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user calculates the office according to the cross-certificate or the implicit certificate. Local The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- 根据权利要求 1 所述的方法,其特征在于,所述方法还包括:The method of claim 1 further comprising:所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server. User, causing the user to calculate the local according to the cross certificate or implicit certificate The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- 根据权利要求 1 或 2 所述的方法,其特征在于,所述方法还包括:The method of claim 1 or 2, wherein the method further comprises:当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE 的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly directly uses the public key of the local CBE or the local CA. The public key is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- 根据权利要求 3 所述的方法,其特征在于,所述网元包括:The method according to claim 3, wherein the network element comprises:核心网节点, CBE , CA ;Core network node, CBE, CA其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是 SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSG 或 SGSN 。The core network node in the LTE network is the MME, and in the UMTS network, the network element entity is an SGSN, in GSM or The network element entity in the GPRS network is an MSG or an SGSN.
- 根据权利要求 1 至 4 任一项所述的方法,其特征在于,所述网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息具体为:The method according to any one of claims 1 to 4, wherein the network element receives a global authentication authority CA list or a determined CA reported by a user. The information is specifically:所述本地核心网节点接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息。The local core network node receives the global authentication authority CA list or the determined CA information reported by the user.
- 根据权利要求 5 所述的方法,其特征在于,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书具体为:The method according to claim 5, wherein said local CA is not in said CA list or local CA is not said determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA:所述本地核心网节点接收用户上报的全球 CA 列表,当本地 CA 不在所述全球 CA 列表中时,当所述本地核心网节点中存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接获取所述本地核心网节点存储的所述任意一个 CA 的交叉证书;The local core network node receives a global CA list reported by the user, when the local CA is not in the global CA In the list, when the cross-certificate of any one of the global CA lists is stored in the local core network node, the any one of the CAs stored by the local core network node is directly obtained. Cross certificate或者当所述本地核心网节点中未存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则从所述全球 CA 列表中选取任意一个 CA ,所述本地核心网节点获取所述选取的任意一个 CA 的交叉证书;Or when the cross-certificate of any one of the global CA lists is not stored in the local core network node, select any one of the global CA lists. a CA, the local core network node acquires a cross certificate of the selected one of the CAs;或者所述本地核心网节点接收用户上报的确定的 CA 信息,当所述本地核心网节点存储所述确定的 CA 的交叉证书时,则直接获取所述本地核心网节点存储的所述确定的 CA 的交叉证书;Or the local core network node receives the determined CA information reported by the user, when the local core network node stores the determined CA When the cross-certificate is obtained, the cross-certificate of the determined CA stored by the local core network node is directly obtained;或者当所述本地核心网节点没有存储所述确定的 CA 的交叉证书时,则从所述确定的 CA 中获取所述确定的 CA 的交叉证书。Or obtaining, when the local core network node does not store the cross-certificate of the determined CA, obtaining the determined CA from the determined CA Cross certificate.
- 根据权利要求 5 或 6 所述的方法,其特征在于,所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息具体为:According to claim 5 or 6 The method is characterized in that the network element sends the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user Said cross-certificate or implicit certificate to calculate said local The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. The PWS message is specifically:所述本地核心网节点将获取的交叉证书,或者所述本地核心网节点将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地的公钥验证所述本地 CBE 下发给用户的 PWS 消息。And sending, by the local core network node, the obtained cross-certificate, or the cross-certificate information obtained by the local core network node to the user, so that the user calculates the locality according to the cross-certificate The public key of the CA, and the user verifies the PWS message sent by the local CBE to the user according to the local public key.
- 根据权利要求 5 至 7 中任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 5 to 7, wherein the method further comprises:所述本地核心网节点将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local core network node sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the cross-certificate information to the user, so that the user calculates the cross-certificate according to the cross-certificate. local The public key of the CA, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- 根据权利要求 8 所述的方法,其特征在于,所述方法还包括:The method of claim 8 further comprising:当所述本地核心网节点存储本地 CBE 和 / 或本地 CA 的公钥时,直接将所述本地 CBE 和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local core network node stores the local CBE and / or the local CA's public key, the local CBE and / or local CA are directly The public key is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the local CBE and/or the public key of the local CA.
- 根据权利要求 1 至 4 任一项所述的方法,其特征在于,所述网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息具体为:The method according to any one of claims 1 to 4, wherein the network element receives a global authentication authority CA list or a determined CA reported by a user. The information is specifically:所述本地 CBE 接收所述本地核心网节点下发的全球认证授权中心 CA 列表或者确定的 CA 信息。Receiving, by the local CBE, a global authentication and authorization center CA list or a determined CA delivered by the local core network node Information.
- 根据权利要求 10 所述的方法,其特征在于,所述本地 CBE 接收所述本地核心网节点下发的全球认证授权中心 CA 列表或者确定的 CA 信息具体为:The method according to claim 10, wherein the local CBE receives a global authentication and authorization center CA delivered by the local core network node. The list or the determined CA information is specifically:所述本地 CBE 接收所述本地核心网节点转发的全球 CA 列表,所述核心网节点将全球 CA 列表直接转发给本地 CBE ;The local CBE receives a global CA list forwarded by the local core network node, and the core network node forwards the global CA list directly to the local CBE ;或者所述核心网节点从所述全球 CA 列表中选取任意一个 CA ,并将所述选取的任意一个 CA 下发给本地 CBE ;Or the core network node selects any CA from the global CA list, and sends the selected one CA to the local CBE. ;或者所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息。Or the local CBE receives the determined CA information forwarded by the local core network node.
- 根据权利要求 11 所述的方法,其特征在于,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书具体为:The method according to claim 11, wherein said local CA is not in said CA list or local CA is not said determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA:当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 存储所述全球 CA 列表中任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书;When the local CBE obtains the global CA list, and when the local CBE stores any one of the global CA lists The implicit certificate of the CA is obtained directly from the local CBE;或者当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 未存储所述全球 CA 列表中任意一个 CA 的隐式证书时,则所述本地 CBE 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书;Or when the local CBE obtains the global CA list, and when the local CBE does not store any one of the global CA lists The implicit CBR, the local CBE selects any CA from the global CA list, and obtains a cross certificate of the selected one of the CAs;或者当本地 CBE 获取的是所述核心网节点从所述全球 CA 列表中选取的任意一个 CA 时,并且当所述本地 CBE 存储所述核心网节点选取的任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书;Or when the local CBE obtains any one of the CAs selected by the core network node from the global CA list, and when the local CBE When storing the implicit certificate of any CA selected by the core network node, the implicit certificate of any one of the CAs is directly obtained from the local CBE;或者当本地 CBE 获取的是所述核心网节点从所述全球 CA 列表中选取的任意一个 CA 时,并且当所述本地 CBE 未存储所述核心网节点选取的任意一个 CA 的隐式证书时,则所述本地 CBE 中获取所述任意一个 CA 的交叉证书;Or when the local CBE obtains any one of the CAs selected by the core network node from the global CA list, and when the local CBE If the implicit certificate of any one of the CAs selected by the core network node is not stored, the local CBE obtains the cross-certificate of the any one of the CAs;或者当所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息,并且当本地 CBE 存储所述确定的 CA 的隐式证书时,则直接从本地 CBE 中获取所述确定的 CA 的隐式证书;Or when the local CBE receives the determined CA information forwarded by the local core network node, and when the local CBE stores the determined CA The implicit certificate of the CA is obtained directly from the local CBE;或者当所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息,且当本地 CBE 未存储所述确定的 CA 的隐式证书时,则获取所述确定的 CA 的交叉证书。Or when the local CBE receives the determined CA information forwarded by the local core network node, and when the local CBE does not store the determined CA When the implicit certificate is obtained, the cross certificate of the determined CA is obtained.
- 根据权利要求 10 至 12 中任一项所述的方法,其特征在于,所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息具体为:According to claims 10 to 12 The method according to any one of the preceding claims, wherein the network element sends the obtained cross-certificate or implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user. Causing the user to calculate the local based on the cross-certificate or implicit certificate The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. The PWS message is specifically:所述本地 CBE 将获取的交叉证书或者隐式证书,或者所述 CBE 将获取的交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The cross-certificate or implicit certificate that the local CBE will acquire, or the CBE And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate. The public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
- 根据权利要求 10 至 13 中任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 10 to 13, wherein the method further comprises:所述本地 CBE 将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local CBE Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user, so that the user Calculating the local according to the cross certificate or implicit certificate The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- 根据权利要求 14 所述的方法,其特征在于,所述方法还包括:The method of claim 14, wherein the method further comprises:当所述本地 CBE 中存储本地 CBE 的公钥和 / 或本地 CA 的公钥时,则直接将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local CBE stores the public key of the local CBE and/or the public key of the local CA, the public key of the local CBE is directly and / Or the public key of the local CA is sent to the user, so that the user verifies the PWS sent by the local CBE to the user according to the local CBE and/or the public key of the local CA. Message.
- 根据权利要求 1 至 4 中任一项所述的方法,其特征在于,所述网元接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息具体为:The method according to any one of claims 1 to 4, wherein the network element receives a global authentication authority CA list or a determined CA reported by a user. The information is specifically:所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息。The local CA receives the global authentication authority CA list or the determined CA information reported by the user.
- 根据权利要求 16 所述的方法,其特征在于,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息具体为 :The method according to claim 16, wherein the local CA receives a global authentication authority CA list or a determined CA reported by the user. The information is specifically as follows:所述本地核心网节点接收用户上报的所述全球 CA 列表,将所述全球 CA 列表转发给所述本地 CBE ,由所述本地 CBE 将所述全球 CA 列表转发给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, forwarding the global CA list to the local CBE, by the local CBE Forwarding the global CA list to the local CA.
- 根据权利要求 17 所述的方法,其特征在于,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书具体为:The method according to claim 17, wherein said local CA is not in said CA list or local CA is not said determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA:当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意一个 CA 的交叉证书;When the local CA obtains the global CA list, and when the local CA stores any one of the global CA lists When the cross-certificate is obtained, the cross-certificate of any one of the CAs is obtained directly from the local CA;或者当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 未存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则所述本地 CA 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书。Or when the local CA obtains the global CA list, and when the local CA does not store any one of the global CA lists The cross-certificate, the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs.
- 根据权利要求 16 所述的方法,其特征在于,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息具体为 :The method according to claim 16, wherein the local CA receives a global authentication authority CA list or a determined CA reported by the user. The information is specifically as follows:所述本地核心网节点接收用户上报的所述全球 CA 列表,将所述全球 CA 列表转发给所述本地 CBE ,由所述本地 CBE 从所述全球 CA 列表中选取任意一个 CA ,并将选取的任意一个 CA 上报给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, forwarding the global CA list to the local CBE, by the local CBE Select any CA from the global CA list, and report any selected CA to the local CA.
- 根据权利要求 19 所述的方法,其特征在于,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书具体为:The method according to claim 19, wherein said local CA is not in said CA list or local CA is not said determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA:当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA 时,并当本地 CA 存储所述任意选取的一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意选取的一个 CA 的交叉证书;When the local CA obtains a CA selected by the local CBE from the global CA list, and is a local CA When the cross-certificate of the arbitrarily selected one of the CAs is stored, the cross-certificate of the arbitrarily selected one of the CAs is directly obtained from the local CA;或者当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA 时,并当本地 CA 未存储所述任意选取的一个 CA 的交叉证书时,则所述本地 CA 获取所述任意选取的一个 CA 的交叉证书。Or when the local CA obtains a CA selected by the local CBE from the global CA list, and is a local CA When the cross-certificate of the arbitrarily selected one of the CAs is not stored, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs.
- 根据权利要求 16 所述的方法,其特征在于,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息具体为 :The method according to claim 16, wherein the local CA receives a global authentication authority CA list or a determined CA reported by the user. The information is specifically as follows:所述本地核心网节点接收用户上报的所述全球 CA 列表,由所述本地核心网节点从所述全球 CA 列表中选取任意一个 CA ,并将所述本地核心网节点选取的任意一个 CA 上报给本地 CBE ,由所述本地 CBE 将所述本地核心网节点选取的任意一个 CA 上报转发给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, where the local core network node selects any CA from the global CA list And reporting, by the local CBE, any CA selected by the local core network node to the local CBE, and forwarding, by the local CBE, any CA that is selected by the local core network node to the local CA .
- 根据权利要求 21 所述的方法,其特征在于,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书具体为:The method according to claim 21, wherein said local CA is not in said CA list or local CA is not said determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA:当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA 存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 直接从本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书;And when the local CA receives any one of the local CBE forwarding, and when the local CA stores any one of the local CBE forwarding The CA obtains the cross-certificate of any CA forwarded by the local CBE directly from the local CA.当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA 未存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。When the local CA receives any one of the local CBE forwarding, and when the local CA does not store any of the local CBE forwarding At the time of the CA, the local CA obtains a cross-certificate of any CA forwarded by the local CBE.
- 根据权利要求 16 所述的方法,其特征在于,所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息具体为 :The method according to claim 16, wherein the local CA receives a global authentication authority CA list or a determined CA reported by the user. The information is specifically as follows:所述本地核心网节点接收用户上报的所述确定的 CA 信息,所述核心网节点将所述确定的 CA 信息转发给所述本地 CBE ,并由所述本地 CBE 将所述确定的 CA 信息转发给所述本地 CA 。Receiving, by the local core network node, the determined CA information reported by the user, where the core network node forwards the determined CA information to the local CBE And forwarding, by the local CBE, the determined CA information to the local CA.
- 根据权利要求 23 所述的方法,其特征在于,所述当本地 CA 不在所述 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书具体为:The method according to claim 23, wherein said local CA is not in said CA list or local CA is not said determined CA Obtaining a cross-certificate or an implicit certificate of any one of the global CA lists; or obtaining a cross-certificate or an implicit certificate of the determined CA:当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA 存储所述确定的 CA 的交叉证书时,则直接从本地 CA 中获取所述确定的 CA 的交叉证书;When the local CA receives the determined CA information forwarded by the local CBE, and when the local CA stores the determined CA When the cross-certificate is obtained, the cross-certificate of the determined CA is obtained directly from the local CA;当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA 未存储所述确定的 CA 的交叉证书,则获取所述确定的 CA 的交叉证书。When the local CA receives the determined CA information forwarded by the local CBE, and when the local CA does not store the determined CA The cross-certificate obtains the cross-certificate of the determined CA.
- 根据权利要求 17 至 24 任一项所述的方法,其特征在于,所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息具体为:According to claims 17 to 24 The method of any one of the preceding claims, wherein the network element sends the obtained cross-certificate or implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the network element The user calculates the local according to the cross certificate or implicit certificate The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. The PWS message is specifically:所述本地 CA 将获取的交叉证书,或者所述本地 CA 将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The cross certificate obtained by the local CA, or the local CA And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA. A public alarm system PWS message that is sent to the user.
- 根据权利要求 17 至 25 任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 17 to 25, wherein the method further comprises:所述本地 CA 将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local CA The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate. The public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- 根据权利要求 26 所述的方法,其特征在于,所述方法还包括 :The method of claim 26, wherein the method further comprises:当所述本地 CA 中存储本地 CBE 的公钥和 / 或本地 CA 的公钥时,则直接将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local CA stores the public key of the local CBE and/or the public key of the local CA, the public key of the local CBE and/or the local is directly The public key of the CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the local CBE and/or the public key of the local CA.
- 一种获取公钥的方法,所述方法包括:A method of obtaining a public key, the method comprising:用户将全球 CA 列表或者确定的 CA 信息上报给所述网元;The user reports the global CA list or the determined CA information to the network element.所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS 消息进行验证。Receiving, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and using the cross certificate or the implicit certificate to the local CBE The PWS message sent to the user is verified.
- 根据权利要求 28 所述的方法,其特征在于,所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS 消息进行验证具体为:According to claim 28 The method is characterized in that: the user receives a cross certificate or an implicit certificate issued by the network element, or cross-certificate or implicit certificate information, and performs local CBE according to the cross-certificate or implicit certificate. The PWS message sent to the user is verified as follows:所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA 的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述 PWS 消息的签名。Receiving, by the user, a cross certificate issued by the network element, or the information of the cross certificate, according to the cross certificate and a CA in the global CA corresponding to the cross certificate The public key of the local CA is calculated according to the public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, according to the local key. The public key of the CBE verifies the signature of the PWS message.
- 根据权利要求 28 所述的方法,其特征在于,所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS 消息进行验证具体为:According to claim 28 The method is characterized in that: the user receives a cross certificate or an implicit certificate issued by the network element, or cross-certificate or implicit certificate information, and performs local CBE according to the cross-certificate or implicit certificate. The PWS message sent to the user is verified as follows:所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE 的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。Receiving, by the user, an implicit certificate issued by the network element, or the information of the implicit certificate, according to the implicit certificate and a CA in the global CA corresponding to the implicit certificate The public key of the local CBE is calculated by the public key of the local CBE, and the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- 根据权利要求 28 所述的方法,其特征在于,所述方法还包括:The method of claim 28, wherein the method further comprises:所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE 公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。Receiving, by the user, the local CBE public key and/or the local CA public key delivered by the network element, according to the local CBE public key and/or the local CA The public key verifies the PWS message delivered by the local CBE.
- 根据权利要求 31 所述的方法,其特征在于,所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE 公钥或者本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证具体为:The method according to claim 31, wherein the user receives a local CBE public key and/or a local CA delivered by the network element. The public key is used to verify the PWS message delivered by the local CBE according to the local CBE public key or the local CA public key.当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE 下发的 PWS 消息;When the user receives the local CBE public key delivered by the network element, the local CBE public key is directly verified according to the local CBE public key. Message或者当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE 下发的 PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。Or when the user receives the local CA public key delivered by the network element, according to the local CA public key and the PWS delivered by the local CBE The implicit certificate in the message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- 一种网元,所述网元包括:A network element, where the network element includes:接收单元,用于接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息;a receiving unit, configured to receive a global certification authority CA list or determined CA information reported by the user;获取单元,用于当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书;An obtaining unit, configured to acquire the global CA when the local CA is not in the global CA list or the local CA is not the determined CA a cross-certificate or an implicit certificate of any CA in the list; or a cross-certificate or an implicit certificate of the determined CA;第一下发单元,用于所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。a first sending unit, configured to send, by the network element, a cross-certificate or an implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- 根据权利要求 33 所述的网元,其特征在于,所述网元还包括上发单元,所述上发单元包括:The network element according to claim 33, wherein the network element further comprises a sending unit, and the sending unit comprises:所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server. User, causing the user to calculate the local according to the cross certificate or implicit certificate The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- 根据权利要求 33 或 34 所述的网元,其特征在于,所述网元还包括第二下发单元,所述第二下单元包括:According to claim 33 or 34 The network element, wherein the network element further includes a second sending unit, where the second lower unit includes:当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE 的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly directly uses the public key of the local CBE or the local CA. The public key is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- 根据权利要求 35 所述的网元,其特征在于,所述网元包括:The network element according to claim 35, wherein the network element comprises:核心网节点, CBE , CA ;Core network node, CBE, CA其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是 SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSG 或 SGSN 。The core network node in the LTE network is the MME, and in the UMTS network, the network element entity is an SGSN, in GSM or The network element entity in the GPRS network is an MSG or an SGSN.
- 根据权利要求 33 至 36 任一项所述的网元,其特征在于,所述接收单元包括第一接收单元,所述第一接收单元包括:According to claims 33 to 36 The network element according to any one of the preceding claims, wherein the receiving unit comprises a first receiving unit, and the first receiving unit comprises:所述本地核心网节点接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息。The local core network node receives the global authentication authority CA list or the determined CA information reported by the user.
- 根据权利要求 37 所述的网元,其特征在于,所述获取单元包括第一获取单元,所述第一获取单元包括:The network element according to claim 37, wherein the obtaining unit comprises a first acquiring unit, and the first acquiring unit comprises:所述本地核心网节点接收用户上报的全球 CA 列表,当本地 CA 不在所述全球 CA 列表中时,当所述本地核心网节点中存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接获取所述本地核心网节点存储的所述任意一个 CA 的交叉证书;The local core network node receives a global CA list reported by the user, when the local CA is not in the global CA In the list, when the cross-certificate of any one of the global CA lists is stored in the local core network node, the any one of the CAs stored by the local core network node is directly obtained. Cross certificate或者当所述本地核心网节点中未存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则从所述全球 CA 列表中选取任意一个 CA ,所述本地核心网节点获取所述选取的任意一个 CA 的交叉证书;Or when the cross-certificate of any one of the global CA lists is not stored in the local core network node, select any one of the global CA lists. a CA, the local core network node acquires a cross certificate of the selected one of the CAs;或者所述本地核心网节点接收用户上报的确定的 CA 信息,当所述本地核心网节点存储所述确定的 CA 的交叉证书时,则直接获取所述本地核心网节点存储的所述确定的 CA 的交叉证书;Or the local core network node receives the determined CA information reported by the user, when the local core network node stores the determined CA When the cross-certificate is obtained, the cross-certificate of the determined CA stored by the local core network node is directly obtained;或者当所述本地核心网节点没有存储所述确定的 CA 的交叉证书时,则从所述确定的 CA 中获取所述确定的 CA 的交叉证书。Or obtaining, when the local core network node does not store the cross-certificate of the determined CA, obtaining the determined CA from the determined CA Cross certificate.
- 根据权利要求 37 或 38 所述的网元,其特征在于,所述第一下发单元包括第三下发单元,所述第三下发单元包括:According to claim 37 or 38 The network element is characterized in that: the first sending unit includes a third sending unit, and the third sending unit includes:所述本地核心网节点将获取的交叉证书,或者所述本地核心网节点将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地的公钥验证所述本地 CBE 下发给用户的 PWS 消息。And sending, by the local core network node, the obtained cross-certificate, or the cross-certificate information obtained by the local core network node to the user, so that the user calculates the locality according to the cross-certificate The public key of the CA, and the user verifies the PWS message sent by the local CBE to the user according to the local public key.
- 根据权利要求 37 至 39 中任一项所述的网元,其特征在于,所述上发单元包括第一上发单元,所述第一上发单元包括:According to claims 37 to 39 The network element according to any one of the preceding claims, wherein the sending unit comprises a first sending unit, and the first sending unit comprises:所述本地核心网节点将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local core network node sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the cross-certificate information to the user, so that the user calculates the cross-certificate according to the cross-certificate. local The public key of the CA, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- 根据权利要求 40 所述的网元,其特征在于,所述第二下发单元包括第四下发单元,所述第四下发单元包括:According to claim 40 The network element is characterized in that: the second sending unit includes a fourth sending unit, and the fourth sending unit includes:当所述本地核心网节点存储本地 CBE 和 / 或本地 CA 的公钥时,直接将所述本地 CBE 和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local core network node stores the local CBE and / or the local CA's public key, the local CBE and / or local CA are directly The public key is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the local CBE and/or the public key of the local CA.
- 根据权利要求 33 至 36 任一项所述的网元,其特征在于,所述接收单元包括第二接收单元,所述第二接收单元包括:According to claims 33 to 36 The network element according to any one of the preceding claims, wherein the receiving unit comprises a second receiving unit, and the second receiving unit comprises:所述本地 CBE 接收所述本地核心网节点下发的全球认证授权中心 CA 列表或者确定的 CA 信息。Receiving, by the local CBE, a global authentication and authorization center CA list or a determined CA delivered by the local core network node Information.
- 根据权利要求 42 所述的网元,其特征在于,所述第二接收单元包括:The network element according to claim 42, wherein the second receiving unit comprises:所述本地 CBE 接收所述本地核心网节点转发的全球 CA 列表,所述核心网节点将全球 CA 列表直接转发给本地 CBE ;The local CBE receives a global CA list forwarded by the local core network node, and the core network node forwards the global CA list directly to the local CBE ;或者所述核心网节点从所述全球 CA 列表中选取任意一个 CA ,并将所述选取的任意一个 CA 下发给本地 CBE ;Or the core network node selects any CA from the global CA list, and sends the selected one CA to the local CBE. ;或者所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息。Or the local CBE receives the determined CA information forwarded by the local core network node.
- 根据权利要求 43 所述的网元,其特征在于,所述获取单元包括第二获取单元,所述第二获取单元包括:The network element according to claim 43, wherein the obtaining unit comprises a second acquiring unit, and the second obtaining unit comprises:当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 存储所述全球 CA 列表中任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书;When the local CBE obtains the global CA list, and when the local CBE stores any one of the global CA lists The implicit certificate of the CA is obtained directly from the local CBE;或者当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 未存储所述全球 CA 列表中任意一个 CA 的隐式证书时,则所述本地 CBE 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书;Or when the local CBE obtains the global CA list, and when the local CBE does not store any one of the global CA lists The implicit CBR, the local CBE selects any CA from the global CA list, and obtains a cross certificate of the selected one of the CAs;或者当本地 CBE 获取的是所述核心网节点从所述全球 CA 列表中选取的任意一个 CA 时,并且当所述本地 CBE 存储所述核心网节点选取的任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书;Or when the local CBE obtains any one of the CAs selected by the core network node from the global CA list, and when the local CBE When storing the implicit certificate of any CA selected by the core network node, the implicit certificate of any one of the CAs is directly obtained from the local CBE;或者当本地 CBE 获取的是所述核心网节点从所述全球 CA 列表中选取的任意一个 CA 时,并且当所述本地 CBE 未存储所述核心网节点选取的任意一个 CA 的隐式证书时,则所述本地 CBE 中获取所述任意一个 CA 的交叉证书;Or when the local CBE obtains any one of the CAs selected by the core network node from the global CA list, and when the local CBE If the implicit certificate of any one of the CAs selected by the core network node is not stored, the local CBE obtains the cross-certificate of the any one of the CAs;或者当所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息,并且当本地 CBE 存储所述确定的 CA 的隐式证书时,则直接从本地 CBE 中获取所述确定的 CA 的隐式证书;Or when the local CBE receives the determined CA information forwarded by the local core network node, and when the local CBE stores the determined CA The implicit certificate of the CA is obtained directly from the local CBE;或者当所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息,且当本地 CBE 未存储所述确定的 CA 的隐式证书时,则获取所述确定的 CA 的交叉证书。Or when the local CBE receives the determined CA information forwarded by the local core network node, and when the local CBE does not store the determined CA When the implicit certificate is obtained, the cross certificate of the determined CA is obtained.
- 根据权利要求 42 至 44 中任一项所述的网元,其特征在于,所述第一下发单元包括第五下发单元,所述第五下发单元包括:According to claims 42 to 44 The network element according to any one of the preceding claims, wherein the first sending unit comprises a fifth sending unit, and the fifth sending unit comprises:所述本地 CBE 将获取的交叉证书或者隐式证书,或者所述 CBE 将获取的交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The cross-certificate or implicit certificate that the local CBE will acquire, or the CBE And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate. The public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
- 根据权利要求 42 至 45 中任一项所述的网元,其特征在于,所述上发单元包括第二上发单元,所述第二上发单元包括:According to claims 42 to 45 The network element according to any one of the preceding claims, wherein the sending unit comprises a second sending unit, and the second sending unit comprises:所述本地 CBE 将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local CBE Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user, so that the user Calculating the local according to the cross certificate or implicit certificate The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- 根据权利要求 46 所述的网元,其特征在于,所述第二下发单元还包括第六下发单元,所述第六下发单元包括:According to claim 46 The network element, wherein the second sending unit further includes a sixth sending unit, where the sixth sending unit includes:当所述本地 CBE 中存储本地 CBE 的公钥和 / 或本地 CA 的公钥时,则直接将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local CBE stores the public key of the local CBE and/or the public key of the local CA, the public key of the local CBE is directly and / Or the public key of the local CA is sent to the user, so that the user verifies the PWS sent by the local CBE to the user according to the local CBE and/or the public key of the local CA. Message.
- 根据权利要求 33 至 36 中所述的任一项所述的网元,其特征在于,所述接收单元包括第三接收单元,所述第三接收单元包括:According to claims 33 to 36 The network element according to any one of the preceding claims, wherein the receiving unit comprises a third receiving unit, and the third receiving unit comprises:所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息。The local CA receives the global authentication authority CA list or the determined CA information reported by the user.
- 根据权利要求 48 所述的网元,其特征在于,所述接收单元包括第三接收单元,所述第三接收单元包括:The network element according to claim 48, wherein the receiving unit comprises a third receiving unit, and the third receiving unit comprises:所述本地核心网节点接收用户上报的所述全球 CA 列表,将所述全球 CA 列表转发给所述本地 CBE ,由所述本地 CBE 将所述全球 CA 列表转发给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, forwarding the global CA list to the local CBE, by the local CBE Forwarding the global CA list to the local CA.
- 根据权利要求 49 所述的网元,其特征在于,所述获取单元包括第三获取单元,所述第三获取单元包括:The network element according to claim 49, wherein the obtaining unit comprises a third obtaining unit, and the third obtaining unit comprises:当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意一个 CA 的交叉证书;When the local CA obtains the global CA list, and when the local CA stores any one of the global CA lists When the cross-certificate is obtained, the cross-certificate of any one of the CAs is obtained directly from the local CA;或者当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 未存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则所述本地 CA 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书。Or when the local CA obtains the global CA list, and when the local CA does not store any one of the global CA lists The cross-certificate, the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs.
- 根据权利要求 48 所述的网元,其特征在于,所述第三接收单元,包括:The network element according to claim 48, wherein the third receiving unit comprises:所述本地核心网节点接收用户上报的所述全球 CA 列表,将所述全球 CA 列表转发给所述本地 CBE ,由所述本地 CBE 从所述全球 CA 列表中选取任意一个 CA ,并将选取的任意一个 CA 上报给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, forwarding the global CA list to the local CBE, by the local CBE Select any CA from the global CA list, and report any selected CA to the local CA.
- 根据权利要求 51 所述的网元,其特征在于,所述第三获取单元,包括 ;The network element according to claim 51, wherein the third obtaining unit comprises:当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA 时,并当本地 CA 存储所述任意选取的一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意选取的一个 CA 的交叉证书;When the local CA obtains a CA selected by the local CBE from the global CA list, and is a local CA When the cross-certificate of the arbitrarily selected one of the CAs is stored, the cross-certificate of the arbitrarily selected one of the CAs is directly obtained from the local CA;或者当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA 时,并当本地 CA 未存储所述任意选取的一个 CA 的交叉证书时,则所述本地 CA 获取所述任意选取的一个 CA 的交叉证书。Or when the local CA obtains a CA selected by the local CBE from the global CA list, and is a local CA When the cross-certificate of the arbitrarily selected one of the CAs is not stored, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs.
- 根据权利要求 48 所述的网元,其特征在于,所述第三接收单元,包括:The network element according to claim 48, wherein the third receiving unit comprises:所述本地核心网节点接收用户上报的所述全球 CA 列表,由所述本地核心网节点从所述全球 CA 列表中选取任意一个 CA ,并将所述本地核心网节点选取的任意一个 CA 上报给本地 CBE ,由所述本地 CBE 将所述本地核心网节点选取的任意一个 CA 上报转发给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, where the local core network node selects any CA from the global CA list And reporting, by the local CBE, any CA selected by the local core network node to the local CBE, and forwarding, by the local CBE, any CA that is selected by the local core network node to the local CA .
- 根据权利要求 53 所述的网元,其特征在于,所述第三获取单元,包括:The network element according to claim 53, wherein the third obtaining unit comprises:当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA 存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 直接从本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书;And when the local CA receives any one of the local CBE forwarding, and when the local CA stores any one of the local CBE forwarding The CA obtains the cross-certificate of any CA forwarded by the local CBE directly from the local CA.当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA 未存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。When the local CA receives any one of the local CBE forwarding, and when the local CA does not store any of the local CBE forwarding At the time of the CA, the local CA obtains a cross-certificate of any CA forwarded by the local CBE.
- 根据权利要求 48 所述的网元,其特征在于,所述第三接收单元,包括:The network element according to claim 48, wherein the third receiving unit comprises:所述本地核心网节点接收用户上报的所述确定的 CA 信息,所述核心网节点将所述确定的 CA 信息转发给所述本地 CBE ,并由所述本地 CBE 将所述确定的 CA 信息转发给所述本地 CA 。Receiving, by the local core network node, the determined CA information reported by the user, where the core network node forwards the determined CA information to the local CBE And forwarding, by the local CBE, the determined CA information to the local CA.
- 根据权利要求 55 所述的网元,其特征在于,所述第三获取单元,包括:The network element according to claim 55, wherein the third obtaining unit comprises:当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA 存储所述确定的 CA 的交叉证书时,则直接从本地 CA 中获取所述确定的 CA 的交叉证书;When the local CA receives the determined CA information forwarded by the local CBE, and when the local CA stores the determined CA When the cross-certificate is obtained, the cross-certificate of the determined CA is obtained directly from the local CA;当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA 未存储所述确定的 CA 的交叉证书,则获取所述确定的 CA 的交叉证书。When the local CA receives the determined CA information forwarded by the local CBE, and when the local CA does not store the determined CA The cross-certificate obtains the cross-certificate of the determined CA.
- 根据权利要求 49 至 56 任一项所述的网元,其特征在于,所述第一下发单元包括第七下发单元,所述第七下发单元包括:According to claims 49 to 56 The network element of any one of the preceding claims, wherein the first sending unit comprises a seventh sending unit, and the seventh sending unit comprises:所述本地 CA 将获取的交叉证书,或者所述本地 CA 将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The cross certificate obtained by the local CA, or the local CA And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA. A public alarm system PWS message that is sent to the user.
- 根据权利要求 49 至 57 任一项所述的网元,其特征在于,所述上发单元包括第三上发单元,所述第三上发单元包括:According to claims 49 to 57 The network element according to any one of the preceding claims, wherein the sending unit comprises a third sending unit, and the third sending unit comprises:所述本地 CA 将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local CA The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate. The public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- 根据权利要求 58 所述的网元,其特征在于,所述第二下发单元还包括第八下发单元,所述第八下发单元包括:According to claim 58 The network element, wherein the second sending unit further includes an eighth sending unit, where the eighth sending unit includes:当所述本地 CA 中存储本地 CBE 的公钥和 / 或本地 CA 的公钥时,则直接将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local CA stores the public key of the local CBE and/or the public key of the local CA, the public key of the local CBE and/or the local is directly The public key of the CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the local CBE and/or the public key of the local CA.
- 一种终端设备,所述终端设备包括:A terminal device, the terminal device comprising:信息上发单元,用于用户将全球 CA 列表或者确定的 CA 信息上报给所述网元;An information sending unit, configured to report, by the user, the global CA list or the determined CA information to the network element;接收验证单元,用于所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS 消息进行验证。Receiving a verification unit, configured to receive, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and localize according to the cross certificate or the implicit certificate The PWS message sent by the CBE to the user is verified.
- 根据权利要求 60 所述的终端设备,其特征在于,所述接收验证单元包括第一接收验证单元,所述第一接收验证单元包括:According to claim 60 The terminal device is characterized in that the receiving and verifying unit includes a first receiving and verifying unit, and the first receiving and verifying unit includes:所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA 的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述 PWS 消息的签名。Receiving, by the user, a cross certificate issued by the network element, or the information of the cross certificate, according to the cross certificate and a CA in the global CA corresponding to the cross certificate The public key of the local CA is calculated according to the public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, according to the local key. The public key of the CBE verifies the signature of the PWS message.
- 根据权利要求 61 所述的终端设备,其特征在于,所述接收验证单元包括第二接收验证单元,所述第二接收验证单元包括:According to claim 61 The terminal device is characterized in that the receiving and verifying unit includes a second receiving and verifying unit, and the second receiving and verifying unit includes:所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE 的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。Receiving, by the user, an implicit certificate issued by the network element, or the information of the implicit certificate, according to the implicit certificate and a CA in the global CA corresponding to the implicit certificate The public key of the local CBE is calculated by the public key of the local CBE, and the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- 根据权利要求 62 所述的终端设备,其特征在于,所述终端设备还包括第三接收验证单元,所述第三接收验证单元包括:According to claim 62 The terminal device further includes a third receiving verification unit, where the third receiving verification unit includes:所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE 公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。Receiving, by the user, the local CBE public key and/or the local CA public key delivered by the network element, according to the local CBE public key and/or the local CA The public key verifies the PWS message delivered by the local CBE.
- 根据权利要求 63 所述的终端设备,其特征在于,所述第三接收验证单元包括:The terminal device according to claim 63, wherein the third receiving verification unit comprises:当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE 下发的 PWS 消息;When the user receives the local CBE public key delivered by the network element, the local CBE public key is directly verified according to the local CBE public key. Message或者当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE 下发的 PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。Or when the user receives the local CA public key delivered by the network element, according to the local CA public key and the PWS delivered by the local CBE The implicit certificate in the message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- 一种网元,所述网元包括:A network element, where the network element includes:接收单元,用于接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息;a receiving unit, configured to receive a global certification authority CA list or determined CA information reported by the user;获取单元,用于当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书;An obtaining unit, configured to acquire the global CA when the local CA is not in the global CA list or the local CA is not the determined CA a cross-certificate or an implicit certificate of any CA in the list; or a cross-certificate or an implicit certificate of the determined CA;第一下发单元,用于所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。a first sending unit, configured to send, by the network element, a cross-certificate or an implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- 根据权利要求 65 所述的网元,其特征在于,所述网元包括处理器,通信接口,存储器和总线;The network element according to claim 65, wherein said network element comprises a processor, a communication interface, a memory and a bus;其中处理器、通信接口、存储器通过总线完成相互间的通信;The processor, the communication interface, and the memory complete communication with each other through the bus;所述通信接口,用于与其他王宇设备进行通信;The communication interface is configured to communicate with other Wangyu devices;所述处理器,用于执行程序;The processor is configured to execute a program;所述存储器,用于存放程序;The memory is configured to store a program;其中程序用于 接收用户上报的全球认证授权中心 CA 列表或确定的 CA 信息;当本地 CA 不在所述全球 CA 列表或本地 CA 不是所述确定的 CA 时,则获取所述全球 CA 列表中任意一个 CA 的交叉证书或隐式证书;或者获取所述确定的 CA 的交叉证书或隐式证书;所述网元将获取的交叉证书或隐式证书,或者所述网元将获取的交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The program is configured to receive a global certificate authority CA list or determined CA information reported by the user; when the local CA is not in the global CA list or local If the CA is not the determined CA, then obtain a cross-certificate or an implicit certificate of any one of the global CA lists; or obtain the determined CA a cross-certificate or an implicit certificate; the network element will send the obtained cross-certificate or the implicit certificate, or the information of the cross-certificate obtained by the network element or the information of the implicit certificate to the user, so that the user according to the Cross-certificate or implicit certificate to calculate the local The public key of the CA or the local cell broadcasts the public key of the entity CBE, and enables the user to verify the public alarm system delivered to the user by the local CBE according to the public key of the local CA or the public key of the local CBE. PWS message.
- 根据权利要求 66 所述的网元,其特征在于,所述网元还包括上发单元,所述上发单元包括:The network element according to claim 66, wherein the network element further comprises a sending unit, wherein the sending unit comprises:所述网元将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The network element sends the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the cross-certificate information or the implicit certificate information to the network server. User, causing the user to calculate the local according to the cross certificate or implicit certificate The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- 根据权利要求 66 或 67 所述的网元,其特征在于,所述网元 还包括第二下发单元,所述第二下单元包括:The network element according to claim 66 or 67, wherein the network element Also included is a second delivery unit, the second lower unit comprising:当所述网元存储本地 CBE 的公钥或者本地 CA 的公钥时,则所述网元直接将所述本地 CBE 的公钥或者本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 的公钥或者本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the network element stores the public key of the local CBE or the public key of the local CA, the network element directly directly uses the public key of the local CBE or the local CA. The public key is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the public key of the local CBE or the public key of the local CA.
- 根据权利要求 68 所述的网元,其特征在于, 所述网元包括:The network element according to claim 68, wherein the network element comprises:核心网节点, CBE , CA ;Core network node, CBE, CA其中,核心网节点在 LTE 网络中所述网元实体是 MME ,在 UMTS 网络中所述网元实体是 SGSN ,在 GSM 或 GPRS 网络中所述网元实体是 MSG 或 SGSN 。The core network node in the LTE network is the MME, and in the UMTS network, the network element entity is an SGSN, in GSM or The network element entity in the GPRS network is an MSG or an SGSN.
- 根据权利要求 66 至 69 任一项所述的网元,其特征在于,所述 接收单元包括第一接收单元,所述第一接收单元包括:A network element according to any one of claims 66 to 69, wherein said said The receiving unit includes a first receiving unit, and the first receiving unit includes:所述本地核心网节点接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息。The local core network node receives the global authentication authority CA list or the determined CA information reported by the user.
- 根据权利要求 70 所述的网元,其特征在于, 所述获取单元包括第一获取单元,所述第一获取单元包括:A network element according to claim 70, wherein The obtaining unit includes a first acquiring unit, where the first acquiring unit includes:所述本地核心网节点接收用户上报的全球 CA 列表,当本地 CA 不在所述全球 CA 列表中时,当所述本地核心网节点中存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接获取所述本地核心网节点存储的所述任意一个 CA 的交叉证书;The local core network node receives a global CA list reported by the user, when the local CA is not in the global CA In the list, when the cross-certificate of any one of the global CA lists is stored in the local core network node, the any one of the CAs stored by the local core network node is directly obtained. Cross certificate或者当所述本地核心网节点中未存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则从所述全球 CA 列表中选取任意一个 CA ,所述本地核心网节点获取所述选取的任意一个 CA 的交叉证书;Or when the cross-certificate of any one of the global CA lists is not stored in the local core network node, select any one of the global CA lists. a CA, the local core network node acquires a cross certificate of the selected one of the CAs;或者所述本地核心网节点接收用户上报的确定的 CA 信息,当所述本地核心网节点存储所述确定的 CA 的交叉证书时,则直接获取所述本地核心网节点存储的所述确定的 CA 的交叉证书;Or the local core network node receives the determined CA information reported by the user, when the local core network node stores the determined CA When the cross-certificate is obtained, the cross-certificate of the determined CA stored by the local core network node is directly obtained;或者当所述本地核心网节点没有存储所述确定的 CA 的交叉证书时,则从所述确定的 CA 中获取所述确定的 CA 的交叉证书。Or obtaining, when the local core network node does not store the cross-certificate of the determined CA, obtaining the determined CA from the determined CA Cross certificate.
- 根据权利要求 70 或 71 所述的网元,其特征在于, 所述第一下发单元包括第三下发单元,所述第三下发单元包括:A network element according to claim 70 or 71, wherein The first sending unit includes a third sending unit, and the third sending unit includes:所述本地核心网节点将获取的交叉证书,或者所述本地核心网节点将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地的公钥验证所述本地 CBE 下发给用户的 PWS 消息。And sending, by the local core network node, the obtained cross-certificate, or the cross-certificate information obtained by the local core network node to the user, so that the user calculates the locality according to the cross-certificate The public key of the CA, and the user verifies the PWS message sent by the local CBE to the user according to the local public key.
- 根据权利要求 70 至 72 中任一项所述的网元,其特征在于, 所述上发单元包括第一上发单元,所述第一上发单元包括:A network element according to any one of claims 70 to 72, characterized in that The sending unit includes a first sending unit, and the first sending unit includes:所述本地核心网节点将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local core network node sends the obtained cross-certificate to the application server, and the application server sends the cross-certificate or the cross-certificate information to the user, so that the user calculates the cross-certificate according to the cross-certificate. local The public key of the CA, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- 根据权利要求 73 所述的网元,其特征在于, 所述第二下发单元还包括还包括第四下发单元,所述第四下发单元包括:A network element according to claim 73, wherein The second sending unit further includes a fourth sending unit, where the fourth sending unit includes:当所述本地核心网节点存储本地 CBE 和 / 或本地 CA 的公钥时,直接将所述本地 CBE 和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local core network node stores the local CBE and / or the local CA's public key, the local CBE and / or local CA are directly The public key is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the local CBE and/or the public key of the local CA.
- 根据权利要求 66 至 69 任一项所述网元,其特征在于, 所述接收单元包括第二接收单元,所述第二接收单元包括:A network element according to any one of claims 66 to 69, characterized in that The receiving unit includes a second receiving unit, and the second receiving unit includes:所述本地 CBE 接收所述本地核心网节点下发的全球认证授权中心 CA 列表或者确定的 CA 信息。Receiving, by the local CBE, a global authentication and authorization center CA list or a determined CA delivered by the local core network node Information.
- 根据权利要求 75 所述的网元,其特征在于, 所述第二接收单元包括:The network element according to claim 75, wherein the second receiving unit comprises:所述本地 CBE 接收所述本地核心网节点转发的全球 CA 列表,所述核心网节点将全球 CA 列表直接转发给本地 CBE ;The local CBE receives a global CA list forwarded by the local core network node, and the core network node forwards the global CA list directly to the local CBE ;或者所述核心网节点从所述全球 CA 列表中选取任意一个 CA ,并将所述选取的任意一个 CA 下发给本地 CBE ;Or the core network node selects any CA from the global CA list, and sends the selected one CA to the local CBE. ;或者所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息。Or the local CBE receives the determined CA information forwarded by the local core network node.
- 根据权利要求 76 所述的网元,其特征在于,所述获取单元包括第二获取单元,所述第二获取单元包括:The network element according to claim 76, wherein the obtaining unit comprises a second acquiring unit, and the second obtaining unit comprises:当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 存储所述全球 CA 列表中任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书;When the local CBE obtains the global CA list, and when the local CBE stores any one of the global CA lists The implicit certificate of the CA is obtained directly from the local CBE;或者当本地 CBE 获取的是所述全球 CA 列表,并且当所述本地 CBE 未存储所述全球 CA 列表中任意一个 CA 的隐式证书时,则所述本地 CBE 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书;Or when the local CBE obtains the global CA list, and when the local CBE does not store any one of the global CA lists The implicit CBR, the local CBE selects any CA from the global CA list, and obtains a cross certificate of the selected one of the CAs;或者当本地 CBE 获取的是所述核心网节点从所述全球 CA 列表中选取的任意一个 CA 时,并且当所述本地 CBE 存储所述核心网节点选取的任意一个 CA 的隐式证书时,则直接从本地 CBE 中获取所述任意一个 CA 的隐式证书;Or when the local CBE obtains any one of the CAs selected by the core network node from the global CA list, and when the local CBE When storing the implicit certificate of any CA selected by the core network node, the implicit certificate of any one of the CAs is directly obtained from the local CBE;或者当本地 CBE 获取的是所述核心网节点从所述全球 CA 列表中选取的任意一个 CA 时,并且当所述本地 CBE 未存储所述核心网节点选取的任意一个 CA 的隐式证书时,则所述本地 CBE 中获取所述任意一个 CA 的交叉证书;Or when the local CBE obtains any one of the CAs selected by the core network node from the global CA list, and when the local CBE If the implicit certificate of any one of the CAs selected by the core network node is not stored, the local CBE obtains the cross-certificate of the any one of the CAs;或者当所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息,并且当本地 CBE 存储所述确定的 CA 的隐式证书时,则直接从本地 CBE 中获取所述确定的 CA 的隐式证书;Or when the local CBE receives the determined CA information forwarded by the local core network node, and when the local CBE stores the determined CA The implicit certificate of the CA is obtained directly from the local CBE;或者当所述本地 CBE 接收所述本地核心网节点转发的确定的 CA 信息,且当本地 CBE 未存储所述确定的 CA 的隐式证书时,则获取所述确定的 CA 的交叉证书。Or when the local CBE receives the determined CA information forwarded by the local core network node, and when the local CBE does not store the determined CA When the implicit certificate is obtained, the cross certificate of the determined CA is obtained.
- 根据权利要求 75 至 77 中任一项所述的 网元,其特征在于,所述第一下发单元包括第五下发单元,所述第五下发单元包括:A method according to any one of claims 75 to 77 The network element is characterized in that: the first sending unit includes a fifth sending unit, and the fifth sending unit includes:所述本地 CBE 将获取的交叉证书或者隐式证书,或者所述 CBE 将获取的交叉证书的信息或者隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The cross-certificate or implicit certificate that the local CBE will acquire, or the CBE And sending the information of the obtained cross-certificate or the information of the implicit certificate to the user, so that the user calculates the public key of the local CA or the local cell broadcast entity CBE according to the cross-certificate or the implicit certificate. The public key, and the user verifies the public alarm system PWS message sent by the local CBE to the user according to the public key of the local CA or the public key of the local CBE.
- 根据权利要求 75 至 78 中任一项所述的网元,其特征在于,所述上发单元包括第二上发单元,所述第二上发单元包括:According to claims 75 to 78 The network element according to any one of the preceding claims, wherein the sending unit comprises a second sending unit, and the second sending unit comprises:所述本地 CBE 将获取的交叉证书或隐式证书上发给应用服务器,由所述应用服务器将所述交叉证书或隐式证书,或者所述交叉证书的信息或隐式证书的信息下发给用户,使得用户根据所述交叉证书或隐式证书计算所述本地 CA 的公钥或者本地小区广播实体 CBE 的公钥,并使得用户根据所述本地 CA 的公钥或者本地 CBE 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local CBE Sending the obtained cross-certificate or the implicit certificate to the application server, and the application server sends the cross-certificate or the implicit certificate, or the information of the cross-certificate or the information of the implicit certificate to the user, so that the user Calculating the local according to the cross certificate or implicit certificate The public key of the CA or the public key of the local cell broadcast entity CBE, and the user verifies the public alarm system PWS of the local CBE delivery user according to the public key of the local CA or the public key of the local CBE. Message.
- 根据权利要求 79 所述的网元,其特征在于,所述第二下发单元还包括第六下发单元,所述第六下发单元包括:According to claim 79 The network element, wherein the second sending unit further includes a sixth sending unit, where the sixth sending unit includes:当所述本地 CBE 中存储本地 CBE 的公钥和 / 或本地 CA 的公钥时,则直接将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local CBE stores the public key of the local CBE and/or the public key of the local CA, the public key of the local CBE is directly and / Or the public key of the local CA is sent to the user, so that the user verifies the PWS sent by the local CBE to the user according to the local CBE and/or the public key of the local CA. Message.
- 根据权利要求 66 至 69 中所述的任一项所述的网元,其特征在于,所述接收单元包括第三接收单元,所述第三接收单元包括:According to claims 66 to 69 The network element according to any one of the preceding claims, wherein the receiving unit comprises a third receiving unit, and the third receiving unit comprises:所述本地 CA 接收用户上报的全球认证授权中心 CA 列表或者确定的 CA 信息。The local CA receives the global authentication authority CA list or the determined CA information reported by the user.
- 根据权利要求 81 所述的网元,其特征在于,所述接收单元包括第三接收单元,所述第三接收单元包括:The network element according to claim 81, wherein the receiving unit comprises a third receiving unit, and the third receiving unit comprises:所述本地核心网节点接收用户上报的所述全球 CA 列表,将所述全球 CA 列表转发给所述本地 CBE ,由所述本地 CBE 将所述全球 CA 列表转发给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, forwarding the global CA list to the local CBE, by the local CBE Forwarding the global CA list to the local CA.
- 根据权利要求 82 所述的网元,其特征在于,所述获取单元包括第三获取单元,所述第三获取单元包括:The network element according to claim 82, wherein the obtaining unit comprises a third obtaining unit, and the third obtaining unit comprises:当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意一个 CA 的交叉证书;When the local CA obtains the global CA list, and when the local CA stores any one of the global CA lists When the cross-certificate is obtained, the cross-certificate of any one of the CAs is obtained directly from the local CA;或者当本地 CA 获取的是所述全球 CA 列表,并且当所述本地 CA 未存储所述全球 CA 列表中任意一个 CA 的交叉证书时,则所述本地 CA 从所述全球 CA 列表中选择任意一个 CA ,并获取所述选择的任意一个 CA 的交叉证书。Or when the local CA obtains the global CA list, and when the local CA does not store any one of the global CA lists The cross-certificate, the local CA selects any CA from the global CA list, and obtains a cross-certificate of the selected one of the CAs.
- 根据权利要求 81 所述的网元,其特征在于,所述第三接收单元,包括:The network element according to claim 81, wherein the third receiving unit comprises:所述本地核心网节点接收用户上报的所述全球 CA 列表,将所述全球 CA 列表转发给所述本地 CBE ,由所述本地 CBE 从所述全球 CA 列表中选取任意一个 CA ,并将选取的任意一个 CA 上报给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, forwarding the global CA list to the local CBE, by the local CBE Select any CA from the global CA list, and report any selected CA to the local CA.
- 根据权利要求 84 所述的网元,其特征在于,所述第三获取单元,包括 ;The network element according to claim 84, wherein the third obtaining unit comprises:当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA 时,并当本地 CA 存储所述任意选取的一个 CA 的交叉证书时,则直接从本地 CA 中获取所述任意选取的一个 CA 的交叉证书;When the local CA obtains a CA selected by the local CBE from the global CA list, and is a local CA When the cross-certificate of the arbitrarily selected one of the CAs is stored, the cross-certificate of the arbitrarily selected one of the CAs is directly obtained from the local CA;或者当本地 CA 获取的是所述本地 CBE 从所述全球 CA 列表中任意选取的一个 CA 时,并当本地 CA 未存储所述任意选取的一个 CA 的交叉证书时,则所述本地 CA 获取所述任意选取的一个 CA 的交叉证书。Or when the local CA obtains a CA selected by the local CBE from the global CA list, and is a local CA When the cross-certificate of the arbitrarily selected one of the CAs is not stored, the local CA obtains the cross-certificate of the arbitrarily selected one of the CAs.
- 根据权利要求 81 所述的网元,其特征在于,所述第三接收单元,包括:The network element according to claim 81, wherein the third receiving unit comprises:所述本地核心网节点接收用户上报的所述全球 CA 列表,由所述本地核心网节点从所述全球 CA 列表中选取任意一个 CA ,并将所述本地核心网节点选取的任意一个 CA 上报给本地 CBE ,由所述本地 CBE 将所述本地核心网节点选取的任意一个 CA 上报转发给所述本地 CA 。Receiving, by the local core network node, the global CA list reported by the user, where the local core network node selects any CA from the global CA list And reporting, by the local CBE, any CA selected by the local core network node to the local CBE, and forwarding, by the local CBE, any CA that is selected by the local core network node to the local CA .
- 根据权利要求 86 所述的网元,其特征在于,所述第三获取单元,包括:The network element according to claim 86, wherein the third obtaining unit comprises:当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA 存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 直接从本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书;And when the local CA receives any one of the local CBE forwarding, and when the local CA stores any one of the local CBE forwarding The CA obtains the cross-certificate of any CA forwarded by the local CBE directly from the local CA.当所述本地 CA 接收所述本地 CBE 转发的任意一个 CA 时,并当本地 CA 未存储所述本地 CBE 转发的任意一个 CA 时,所述本地 CA 获取所述本地 CBE 转发的任意一个 CA 的交叉证书。When the local CA receives any one of the local CBE forwarding, and when the local CA does not store any of the local CBE forwarding At the time of the CA, the local CA obtains a cross-certificate of any CA forwarded by the local CBE.
- 根据权利要求 81 所述的网元,其特征在于,所述第三接收单元,包括:The network element according to claim 81, wherein the third receiving unit comprises:所述本地核心网节点接收用户上报的所述确定的 CA 信息,所述核心网节点将所述确定的 CA 信息转发给所述本地 CBE ,并由所述本地 CBE 将所述确定的 CA 信息转发给所述本地 CA 。Receiving, by the local core network node, the determined CA information reported by the user, where the core network node forwards the determined CA information to the local CBE And forwarding, by the local CBE, the determined CA information to the local CA.
- 根据权利要求 88 所述的网元,其特征在于,所述第三获取单元,包括:The network element according to claim 88, wherein the third obtaining unit comprises:当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA 存储所述确定的 CA 的交叉证书时,则直接从本地 CA 中获取所述确定的 CA 的交叉证书;When the local CA receives the determined CA information forwarded by the local CBE, and when the local CA stores the determined CA When the cross-certificate is obtained, the cross-certificate of the determined CA is obtained directly from the local CA;当本地 CA 接收由本地 CBE 转发的确定的 CA 信息时,并当本地 CA 未存储所述确定的 CA 的交叉证书,则获取所述确定的 CA 的交叉证书。When the local CA receives the determined CA information forwarded by the local CBE, and when the local CA does not store the determined CA The cross-certificate obtains the cross-certificate of the determined CA.
- 根据权利要求 82 至 89 任一项所述的网元,其特征在于,所述第一下发单元包括第七下发单元,所述第七下发单元包括:According to claims 82 to 89 The network element of any one of the preceding claims, wherein the first sending unit comprises a seventh sending unit, and the seventh sending unit comprises:所述本地 CA 将获取的交叉证书,或者所述本地 CA 将获取的交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发给用户的公共报警系统 PWS 消息。The cross certificate obtained by the local CA, or the local CA And sending the obtained cross-certificate information to the user, so that the user calculates the public key of the local CA according to the cross-certificate, and causes the user to verify the local CBE according to the public key of the local CA. A public alarm system PWS message that is sent to the user.
- 根据权利要求 82 至 90 任一项所述的网元,其特征在于,所述上发单元包括第三上发单元,所述第三上发单元包括:According to claims 82 to 90 The network element according to any one of the preceding claims, wherein the sending unit comprises a third sending unit, and the third sending unit comprises:所述本地 CA 将获取的交叉证书上发给应用服务器,由所述应用服务器将所述交叉证书,或者所述交叉证书的信息下发给用户,使得用户根据所述交叉证书计算所述本地 CA 的公钥,并使得用户根据所述本地 CA 的公钥验证本地 CBE 下发用户的公共报警系统 PWS 消息。The local CA The obtained cross-certificate is sent to the application server, and the cross-certificate or the cross-certificate information is sent to the user by the application server, so that the user calculates the local CA according to the cross-certificate. The public key, and the user verifies the public alarm system PWS message delivered by the local CBE according to the public key of the local CA.
- 根据权利要求 91 所述的网元,其特征在于,所述第二下发单元还包括第八下发单元,所述第八下发单元包括:According to claim 91 The network element, wherein the second sending unit further includes an eighth sending unit, where the eighth sending unit includes:当所述本地 CA 中存储本地 CBE 的公钥和 / 或本地 CA 的公钥时,则直接将所述本地 CBE 的公钥和 / 或本地 CA 的公钥下发给用户,使得用户根据所述本地 CBE 和 / 或本地 CA 的公钥验证本地 CBE 下发给用户的 PWS 消息。When the local CA stores the public key of the local CBE and/or the public key of the local CA, the public key of the local CBE and/or the local is directly The public key of the CA is sent to the user, so that the user verifies the PWS message sent by the local CBE to the user according to the local CBE and/or the public key of the local CA.
- 一种终端设备,所述终端设备包括:A terminal device, the terminal device comprising:信息上发单元,用于用户将全球 CA 列表或者确定的 CA 信息上报给所述网元;An information sending unit, configured to report, by the user, the global CA list or the determined CA information to the network element;接收验证单元,用于所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS 消息进行验证。Receiving a verification unit, configured to receive, by the user, a cross certificate or an implicit certificate issued by the network element, or a cross certificate or an implicit certificate, and localize according to the cross certificate or the implicit certificate The PWS message sent by the CBE to the user is verified.
- 根据权利要求 93 所述的终端设备,其特征在于,所述网元包括处理器,通信接口,存储器和总线;The terminal device according to claim 93, wherein said network element comprises a processor, a communication interface, a memory and a bus;其中处理器、通信接口、存储器通过总线完成相互间的通信;The processor, the communication interface, and the memory complete communication with each other through the bus;所述通信接口,用于与其他网元进行通信;The communication interface is configured to communicate with other network elements;所述处理器,用于执行程序;The processor is configured to execute a program;所述存储器,用于存放程序;The memory is configured to store a program;其中程序用于 用户将全球 CA 列表或者确定的 CA 信息上报给所述网元;所述用户接收所述网元下发的交叉证书或者隐式证书,或者交叉证书或隐式证书的信息,并根据所述交叉证书或者隐式证书对本地 CBE 下发给用户的 PWS 消息进行验证。The program is used by the user to list the global CA or determine the CA. The information is reported to the network element; the user receives the cross certificate or the implicit certificate issued by the network element, or the information of the cross certificate or the implicit certificate, and the local CBE is performed according to the cross certificate or the implicit certificate. Sent to the user The PWS message is verified.
- 根据权利要求 94 所述的终端设备,其特征在于,所述接收验证单元包括第一接收验证单元,所述第一接收验证单元包括:According to claim 94 The terminal device is characterized in that the receiving and verifying unit includes a first receiving and verifying unit, and the first receiving and verifying unit includes:所述用户接收所述网元下发的交叉证书,或者所述交叉证书的信息,根据所述交叉证书和所述交叉证书对应的全球 CA 中的一个 CA 的公钥计算本地 CA 的公钥,根据计算得到的所述本地 CA 的公钥根据本地 CBE 下发的 PWS 消息中的隐式证书计算出本地 CBE 的公钥,根据所述本地 CBE 的公钥验证所述 PWS 消息的签名。Receiving, by the user, a cross certificate issued by the network element, or the information of the cross certificate, according to the cross certificate and a CA in the global CA corresponding to the cross certificate The public key of the local CA is calculated according to the public key of the local CA, and the public key of the local CBE is calculated according to the implicit certificate in the PWS message delivered by the local CBE, according to the local key. The public key of the CBE verifies the signature of the PWS message.
- 根据权利要求 95 所述的终端设备,其特征在于,所述接收验证单元包括第二接收验证单元,所述第二接收验证单元包括:According to claim 95 The terminal device is characterized in that the receiving and verifying unit includes a second receiving and verifying unit, and the second receiving and verifying unit includes:所述用户接收所述网元下发的隐式证书,或者所述隐式证书的信息,根据所述隐式证书和所述隐式证书对应的全球 CA 中的一个 CA 的公钥计算本地 CBE 的公钥,所述用户根据计算出的所述本地 CBE 的公钥验证所述本地 CBE 下发的 PWS 消息的签名。Receiving, by the user, an implicit certificate issued by the network element, or the information of the implicit certificate, according to the implicit certificate and a CA in the global CA corresponding to the implicit certificate The public key of the local CBE is calculated by the public key of the local CBE, and the user verifies the signature of the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
- 根据权利要求 96 所述的终端设备,其特征在于,所述终端设备还包括第三接收验证单元,所述第三接收验证单元包括:According to claim 96 The terminal device further includes a third receiving verification unit, where the third receiving verification unit includes:所述用户接收所述网元下发的本地 CBE 公钥和 / 或本地 CA 公钥,根据所述本地 CBE 公钥和 / 或本地 CA 公钥对本地 CBE 下发的 PWS 消息进行验证。Receiving, by the user, the local CBE public key and/or the local CA public key delivered by the network element, according to the local CBE public key and/or the local CA The public key verifies the PWS message delivered by the local CBE.
- 根据权利要求 97 所述的终端设备,其特征在于,所述第三接收验证单元包括:The terminal device according to claim 97, wherein the third receiving verification unit comprises:当所述用户接收所述网元下发的本地 CBE 公钥时,直接根据所述本地 CBE 公钥验证本地 CBE 下发的 PWS 消息;When the user receives the local CBE public key delivered by the network element, the local CBE public key is directly verified according to the local CBE public key. Message或者当所述用户接收所述网元下发的本地 CA 公钥时,根据所述本地 CA 公钥和所述本地 CBE 下发的 PWS 消息中的隐式证书计算本地 CBE 的公钥,根据计算出的所述本地 CBE 的公钥对本地 CBE 下发的 PWS 消息进行验证。Or when the user receives the local CA public key delivered by the network element, according to the local CA public key and the PWS delivered by the local CBE The implicit certificate in the message calculates the public key of the local CBE, and verifies the PWS message delivered by the local CBE according to the calculated public key of the local CBE.
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201280029860.7A CN103931214B (en) | 2012-11-08 | 2012-11-08 | A kind of method and apparatus for obtaining public key |
PCT/CN2012/084291 WO2014071585A1 (en) | 2012-11-08 | 2012-11-08 | Method and device for obtaining public key |
JP2015540982A JP2015535417A (en) | 2012-11-08 | 2012-11-08 | Method and apparatus for obtaining a public key |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/CN2012/084291 WO2014071585A1 (en) | 2012-11-08 | 2012-11-08 | Method and device for obtaining public key |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2014071585A1 true WO2014071585A1 (en) | 2014-05-15 |
Family
ID=50683924
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2012/084291 WO2014071585A1 (en) | 2012-11-08 | 2012-11-08 | Method and device for obtaining public key |
Country Status (3)
Country | Link |
---|---|
JP (1) | JP2015535417A (en) |
CN (1) | CN103931214B (en) |
WO (1) | WO2014071585A1 (en) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN106411528B (en) * | 2016-10-17 | 2019-06-14 | 重庆邮电大学 | Lightweight authentication key negotiation method based on implicit certificate |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101242630A (en) * | 2007-02-05 | 2008-08-13 | 华为技术有限公司 | Method, device and network system for security algorithm negotiation |
CN101645877A (en) * | 2008-08-07 | 2010-02-10 | 华为技术有限公司 | Method, system and network node for consulting cipher key derivative function |
CN102440012A (en) * | 2009-04-15 | 2012-05-02 | 华为技术有限公司 | Method, apparatus and system for receiving public warning system (pws) messages |
CN102611553A (en) * | 2011-01-25 | 2012-07-25 | 华为技术有限公司 | Method for realizing digital signature, user equipment and core network node equipment |
WO2012145901A1 (en) * | 2011-04-27 | 2012-11-01 | Nokia Corporation | Method and apparatus for providing a public warning |
Family Cites Families (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB0428596D0 (en) * | 2004-12-24 | 2005-08-10 | Qinetiq Ltd | Public key infrastructures |
US8457307B2 (en) * | 2007-07-17 | 2013-06-04 | Certicom Corp. | Method and system for generating implicit certificates and applications to identity-based encryption (IBE) |
WO2010129694A1 (en) * | 2009-05-05 | 2010-11-11 | Certicom Corp. | Self-signed implicit certificates |
JP5448892B2 (en) * | 2010-02-03 | 2014-03-19 | 三菱電機株式会社 | Certificate verification system, path constraint information generation apparatus, certificate verification apparatus, and certificate verification method |
EP3364594B1 (en) * | 2011-02-11 | 2020-08-05 | BlackBerry Limited | Using a single certificate request to generate credentials with multiple ecqv certificates |
-
2012
- 2012-11-08 WO PCT/CN2012/084291 patent/WO2014071585A1/en active Application Filing
- 2012-11-08 CN CN201280029860.7A patent/CN103931214B/en active Active
- 2012-11-08 JP JP2015540982A patent/JP2015535417A/en active Pending
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101242630A (en) * | 2007-02-05 | 2008-08-13 | 华为技术有限公司 | Method, device and network system for security algorithm negotiation |
CN101645877A (en) * | 2008-08-07 | 2010-02-10 | 华为技术有限公司 | Method, system and network node for consulting cipher key derivative function |
CN102440012A (en) * | 2009-04-15 | 2012-05-02 | 华为技术有限公司 | Method, apparatus and system for receiving public warning system (pws) messages |
CN102611553A (en) * | 2011-01-25 | 2012-07-25 | 华为技术有限公司 | Method for realizing digital signature, user equipment and core network node equipment |
WO2012145901A1 (en) * | 2011-04-27 | 2012-11-01 | Nokia Corporation | Method and apparatus for providing a public warning |
Also Published As
Publication number | Publication date |
---|---|
JP2015535417A (en) | 2015-12-10 |
CN103931214A (en) | 2014-07-16 |
CN103931214B (en) | 2018-06-15 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2015027485A1 (en) | Method of remotely changing subscription and apparatus thereof | |
WO2019107977A1 (en) | Method and electronic device for providing communication service | |
WO2020251302A1 (en) | Method and system for handling of closed access group related procedure | |
WO2021006691A1 (en) | Method and device for routing data packet, and method and device for controlling data packet transmission | |
WO2020204501A1 (en) | Method for supporting access to closed network, ue, base station and readable storage medium | |
WO2017123002A1 (en) | Method and equipment for determining iot service, and method and equipment for controlling iot service behavior | |
WO2014063360A1 (en) | Control method and device for service access | |
WO2015096160A1 (en) | Method and device for keeping service continuity | |
CN105723648A (en) | Key configuration method, system and apparatus | |
WO2021150014A1 (en) | Self-optimization method and device | |
WO2014187037A1 (en) | Stream forwarding method, device and system | |
EP3420754A1 (en) | Method and enb equipment for supporting seamless handover | |
WO2020116899A1 (en) | Method and equipment for handover | |
WO2015139232A1 (en) | Application recommendation method, system and server | |
WO2022045789A1 (en) | Method and apparatus for recovering profile in case of device change failure | |
WO2022154599A1 (en) | Method and device for supporting communication by using satellite in wireless communication system | |
WO2019177397A1 (en) | Method and apparatus for establishing radio bearer | |
WO2020080909A1 (en) | Method and apparatus for handling remote profile management exception | |
WO2012165794A2 (en) | System and method for simultaneous data transmission service in heterogeneous network | |
WO2020222578A1 (en) | Session and mobility management method using nas protocols | |
WO2017096596A1 (en) | Unmanned aerial vehicle authentication method and system, and secure communication method and system | |
WO2023022558A1 (en) | Method and device for providing event in wireless communication system | |
WO2018143769A1 (en) | Method and device for controlling data transmission, method and apparatus for controlling continuity of ue | |
WO2017171506A1 (en) | Method and enb equipment for supporting seamless handover | |
WO2022108393A1 (en) | Method and device for communication using fronthaul interface |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 12887868 Country of ref document: EP Kind code of ref document: A1 |
|
ENP | Entry into the national phase |
Ref document number: 2015540982 Country of ref document: JP Kind code of ref document: A |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 12887868 Country of ref document: EP Kind code of ref document: A1 |